Vulnerability Description
Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to manipulate cookie attributes by injecting arbitrary values through the unsanitized X-Forwarded-Prefix HTTP header used in Set-Cookie path attributes. Attackers can exploit a misconfigured reverse proxy to downgrade SameSite protection and enable cross-origin authenticated requests, bypassing cookie security controls.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/vrana/adminer/issues/1298
- https://github.com/vrana/adminer/releases#release-v5.4.3
- https://github.com/vrana/adminer/security/advisories/GHSA-c533-9qwm-8w5h
- https://www.vulncheck.com/advisories/adminer-cookie-injection-via-x-forwarded-pr
FAQ
What is CVE-2026-63771?
CVE-2026-63771 is a vulnerability with a CVSS score of 7.1 (HIGH). Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to manipulate cookie attributes by injecting arbitrary values through the unsanitized X-Forwarded-Prefix HTTP heade...
How severe is CVE-2026-63771?
CVE-2026-63771 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-63771?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.