A vulnerability labeled as problematic has been found in vrana Adminer up to 5.4.2. This affects an unknown function of the component Cookie. Executing a manipulation of the argument X-Forwarded-Prefix can lead to permissive cross-domain policy with untrusted domains.

This vulnerability is registered as CVE-2026-63771. It is possible to launch the attack remotely. No exploit is available.