CVE-2026-63771
HIGHAdminer < 5.4.3 Cookie Injection via X-Forwarded-Prefix Header
Title source: cnaDescription
Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to manipulate cookie attributes by injecting arbitrary values through the unsanitized X-Forwarded-Prefix HTTP header used in Set-Cookie path attributes. Attackers can exploit a misconfigured reverse proxy to downgrade SameSite protection and enable cross-origin authenticated requests, bypassing cookie security controls.
References (4)
Core 4
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA--c533-9qwm-8w5h)
https://github.com/vrana/adminer/security/advisories/GHSA-c533-9qwm-8w5h
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/adminer-cookie-injection-via-x-forwarded-prefix-header
Exploit technical-description
exploit
issue-tracking
Researcher Disclosure
https://github.com/vrana/adminer/issues/1298
Scores
CVSS v3
7.1
EPSS
0.0024
EPSS Percentile
15.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-113
Status
published
Products (1)
vrana/adminer
< 5.4.3
Published
Jul 20, 2026
Tracked Since
Jul 21, 2026