CVE-2026-63771 MEDIUM

CVE-2026-63771: Adminer < 5.4.3 Cookie Injection via X-Forwarded-Prefix Header

Vendor Vrana
Product adminer
Weakness CWE-113 · HTTP response splitting
Published July 20, 2026
Last update July 21, 2026

CVSS base score

6.0/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to manipulate cookie attributes by injecting arbitrary values through the unsanitized X-Forwarded-Prefix HTTP header used in Set-Cookie path attributes. Attackers can exploit a misconfigured reverse proxy to downgrade SameSite protection and enable cross-origin authenticated requests, bypassing cookie security controls.

Key dates

02Disclosure timeline

July 20, 2026 CVE published
July 21, 2026 Record updated