Junglewise Threat Intelligence

CVE-2026-16434: Adminer X-Forwarded-Prefix backslash bypass in cookie path validation

CVE-2026-16434 · Severity: info · CVSS 2.3 · Published 2026-08-25

Vendors: Vrana.

Executive brief

Adminer is a popular web-based database administration tool. Versions 4.6.0 through 5.5.0 contain an incomplete security fix that allows attackers to manipulate HTTP cookie scope through a backslash character in the X-Forwarded-Prefix header. Exploitation requires a misconfigured or absent reverse proxy that allows clients to set this header. The impact is limited to incorrect cookie path scoping, posing minimal direct security risk.

Technical details

This vulnerability is an incomplete fix for a prior X-Forwarded-Prefix validation flaw (GHSA-8478-xrj3-h9c2). The validation regex in bootstrap.inc.php uses ~^/[^/]~ to block network-path references like //evil.com, but fails to exclude backslash characters. A payload like /\evil.com passes this check; since browsers normalize backslash to forward slash, the tainted value persists into REQUEST_URI and reaches the cookie_path() function (functions.inc.php:324), affecting the Set-Cookie Path attribute. Exploitation requires that the application or upstream proxy allows clients to set the X-Forwarded-Prefix header. The vulnerability was patched in version 5.5.1 with a corrected validation regex that properly rejects backslash characters.

Affected products

  • vrana Adminer 4.6.0 through 5.5.0 (fixed in 5.5.1)

Timeline

  • 2026-07-21: disclosed: GHSA-fr74-9mf9-gf44 published
  • 2026-08-25: patched: Patched in version 5.5.1

References