{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/adminer--5.4.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-63771"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Adminer \u003c 5.4.3"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","cookie-injection","cve","CWE-113"],"_cs_type":"advisory","_cs_vendors":["vrana"],"content_html":"\u003cp\u003eAdminer, a database management tool, is affected by a cookie injection vulnerability, identified as CVE-2026-63771, impacting versions before 5.4.3. This flaw stems from the tool's unsanitized use of the \u003ccode\u003eX-Forwarded-Prefix\u003c/code\u003e HTTP header when setting \u003ccode\u003eSet-Cookie\u003c/code\u003e path attributes. Attackers can exploit this by sending a specially crafted \u003ccode\u003eX-Forwarded-Prefix\u003c/code\u003e header, particularly when Adminer is deployed behind a misconfigured reverse proxy. Successful exploitation allows for the manipulation of cookie attributes, such as downgrading SameSite protection, which can lead to the enabling of cross-origin authenticated requests and bypassing critical cookie security controls. This can result in session hijacking or unauthorized access to the Adminer interface, compromising database management capabilities.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker identifies an Adminer instance running behind a misconfigured reverse proxy.\u003c/li\u003e\n\u003cli\u003eThe attacker sends an HTTP request to the Adminer instance, including a crafted \u003ccode\u003eX-Forwarded-Prefix\u003c/code\u003e HTTP header containing special characters (e.g., \u003ccode\u003e;\u003c/code\u003e, \u003ccode\u003e%0d%0a\u003c/code\u003e, \u003ccode\u003e=\u003c/code\u003e) intended for cookie attribute injection.\u003c/li\u003e\n\u003cli\u003eThe misconfigured reverse proxy forwards this request, and Adminer processes the unsanitized \u003ccode\u003eX-Forwarded-Prefix\u003c/code\u003e header when generating a \u003ccode\u003eSet-Cookie\u003c/code\u003e response.\u003c/li\u003e\n\u003cli\u003eAdminer injects the attacker-supplied values from \u003ccode\u003eX-Forwarded-Prefix\u003c/code\u003e directly into the \u003ccode\u003eSet-Cookie\u003c/code\u003e path attributes of the HTTP response.\u003c/li\u003e\n\u003cli\u003eThis injection allows the attacker to manipulate cookie attributes, such as downgrading SameSite protection or setting arbitrary cookie properties.\u003c/li\u003e\n\u003cli\u003eBy successfully manipulating the \u003ccode\u003eSet-Cookie\u003c/code\u003e header, the attacker enables cross-origin authenticated requests that would normally be prevented by browser security policies.\u003c/li\u003e\n\u003cli\u003eThe attacker then leverages this weakened cookie security to perform unauthorized actions as an authenticated user from a different origin, bypassing standard browser security controls (e.g., session hijacking, unauthorized database access).\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-63771 allows attackers to bypass critical cookie security controls, potentially leading to unauthorized access to the Adminer interface and the underlying databases it manages. This can result in session hijacking, data exposure, data tampering, or unauthorized administrative actions within the affected environment. While no specific victim counts or targeted sectors are mentioned, any organization using vulnerable Adminer versions behind a misconfigured reverse proxy is at risk of compromising their database management infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-63771 by updating Adminer to version 5.4.3 or newer immediately.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule \u0026quot;Detect CVE-2026-63771 Exploitation Attempts via X-Forwarded-Prefix\u0026quot; to your SIEM and tune for your environment, focusing on webserver logs.\u003c/li\u003e\n\u003cli\u003eConfigure reverse proxies to properly sanitize or remove the \u003ccode\u003eX-Forwarded-Prefix\u003c/code\u003e header before forwarding requests to backend applications if it is not explicitly required.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-20T19:27:01Z","date_published":"2026-07-20T19:27:01Z","id":"https://feed.craftedsignal.io/briefs/2026-07-adminer-cookie-injection/","summary":"Adminer versions prior to 5.4.3 are vulnerable to a cookie injection flaw, which allows attackers to manipulate cookie attributes by injecting arbitrary values through the unsanitized X-Forwarded-Prefix HTTP header, enabling cross-origin authenticated requests and bypassing cookie security controls.","title":"Adminer Cookie Injection Vulnerability via X-Forwarded-Prefix Header (CVE-2026-63771)","url":"https://feed.craftedsignal.io/briefs/2026-07-adminer-cookie-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Adminer \u003c 5.4.3","version":"https://jsonfeed.org/version/1.1"}