Junglewise Threat Intelligence

CVE-2026-63771: Vrana Adminer cookie injection via X-Forwarded-Prefix header

CVE-2026-63771 · Severity: high · CVSS 7.1 · Published 2026-07-20

Vendors: Vrana.

Executive brief

Adminer, a popular web-based database management tool, is vulnerable to a security flaw that allows attackers to manipulate browser cookies. By sending a specially crafted web request through a misconfigured proxy server, an attacker can trick a user's browser into sending sensitive session information to a server controlled by the attacker. This could lead to unauthorized access to the database management interface and the theft of database credentials.

Technical details

Adminer versions 4.6.0 through 5.4.2 are vulnerable to cookie attribute injection (CWE-113) because the application unsafely prepends the 'X-Forwarded-Prefix' HTTP header to the 'REQUEST_URI' global variable. This tainted value is subsequently used to manually construct 'Set-Cookie' headers and configure session cookie parameters without sanitizing semicolons or other attribute delimiters. An attacker can exploit this in environments where a reverse proxy forwards client-supplied headers to inject attributes such as 'Domain', 'SameSite=None', or 'Secure'. This can be used to leak the 'adminer_sid' (session ID) and 'adminer_key' (database encryption key) to an attacker-controlled domain or to bypass CSRF protections by downgrading SameSite attributes. The issue is fixed in version 5.4.3 by escaping the REQUEST_URI.

Affected products

  • vrana Adminer >= 4.6.0, <= 5.4.2

Timeline

  • 2026-06-02: disclosed: Vulnerability reported to vendor
  • 2026-07-09: patched: Version 5.4.3 released with fix
  • 2026-07-20: advisory: NVD publication date

References