CVE-2026-34959

Adminer before 5.5.0 Open Redirect via X-Forwarded-Prefix

Adminer 4.6.0 before 5.5.0 prepends the client-supplied X-Forwarded-Prefix header to $_SERVER["REQUEST_URI"] with no trusted-proxy check and no validation of the prefix value. An attacker can supply an absolute URL (e.g. X-Forwarded-Prefix: https://evil.example) that flows into Location redirect headers, the Set-Cookie path attribute, and self-referential links. This enables an authenticated open redirect after state-changing POSTs, unauthenticated control of the session cookie path attribute, and poisoning of self-referential links; CR/LF cannot be injected, so header splitting/XSS is not possible.


We have discovered 274 live websites that are affected by CVE-2026-34959.

Run a Free Instant Scan




Affected Software

Product  Adminer
Category Database Managers
Vulnerable Domains274 live websites (100% of Adminer install base)
Vulnerable Versions
  • from 0 through 5.5
Vulnerable Versions Count17 versions ( 94% of all versions)



Details

  • Published - Aug 25, 2026
  • Updated - Aug 26, 2026

Credits

  • Infinit3i (reporter)

Website Distribution by Country

Number of websites using CVE-2026-34959
United States44 websites



Czech Republic87 websites
Germany55 websites
France26 websites
Sweden9 websites
Slovakia9 websites
Belgium6 websites
Australia4 websites
China4 websites
Spain4 websites

Website Distribution by TLD

Number of websites using CVE-2026-34959
.cz83 websites
.com62 websites
.de24 websites
.net19 websites
.eu14 websites
.fr8 websites
.se7 websites
.be5 websites
.ch5 websites
.ru4 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-34959

Top websites that are affected by CVE-2026-34959. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.********.com Czech Republic**,***
*******.*****.cz Czech Republic***,***
******.*************.cz Czech Republic***,***
*******.***.cn China***,***
***.*******.net Poland*,***,***
***.*************.de Germany*,***,***
****.********.net United States*,***,***
********.cz Germany*,***,***
***.**************.de Germany*,***,***
*****************.*******************.de Germany*,***,***
See full domain list

FAQ

A total of 274 websites have been identified as vulnerable to CVE-2026-34959, based on global website indexing conducted by WebTechSurvey.
The Adminer is affected by the CVE-2026-34959 vulnerability.
Adminer versions up to 5.5 are vulnerable to CVE-2026-34959.
CVE-2026-34959 is resolved in version 5.5 of Adminer.