Adminer 4.6.0 before 5.5.0 prepends the client-supplied X-Forwarded-Prefix header to $_SERVER["REQUEST_URI"] with no trusted-proxy check and no validation of the prefix value. An attacker can supply an absolute URL (e.g. X-Forwarded-Prefix: https://evil.example) that flows into Location redirect headers, the Set-Cookie path attribute, and self-referential links. This enables an authenticated open redirect after state-changing POSTs, unauthenticated control of the session cookie path attribute, and poisoning of self-referential links; CR/LF cannot be injected, so header splitting/XSS is not possible.
We have discovered 274 live websites that are affected by CVE-2026-34959.
| Product | |
| Category | Database Managers |
| Vulnerable Domains | 274 live websites (100% of Adminer install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 17 versions ( 94% of all versions) |
| 44 websites | |
| 87 websites | |
| 55 websites | |
| 26 websites | |
| 9 websites | |
| 9 websites | |
| 6 websites | |
| 4 websites | |
| 4 websites | |
| 4 websites |
| .cz | 83 websites |
| .com | 62 websites |
| .de | 24 websites |
| .net | 19 websites |
| .eu | 14 websites |
| .fr | 8 websites |
| .se | 7 websites |
| .be | 5 websites |
| .ch | 5 websites |
| .ru | 4 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.********.com | **,*** | ||
| *******.*****.cz | ***,*** | ||
| ******.*************.cz | ***,*** | ||
| *******.***.cn | ***,*** | ||
| ***.*******.net | *,***,*** | ||
| ***.*************.de | *,***,*** | ||
| ****.********.net | *,***,*** | ||
| ********.cz | *,***,*** | ||
| ***.**************.de | *,***,*** | ||
| *****************.*******************.de | *,***,*** |
FAQ