CVE-2026-41448
CRITICALAdGuard Home Authentication Bypass via Path Traversal in Admin-Token Cookie
Title source: cnaDescription
AdGuard Home, when started with the --glinet flag, contains an authentication bypass vulnerability that allows unauthenticated attackers to gain full admin access by supplying a path traversal sequence in the Admin-Token cookie, exploiting unsanitized string concatenation in the token file path construction within the authglinet middleware. Attackers can craft a request with a traversal payload in the Admin-Token header to redirect file reads to arbitrary paths.
References (2)
Core 2
Core References
Release Notes release-notes
https://github.com/AdguardTeam/AdGuardHome/releases/tag/v0.107.77
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/adguard-home-authentication-bypass-via-path-traversal-in-admin-token-cookie
Scores
CVSS v3
9.4
EPSS
0.0053
EPSS Percentile
40.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-22
Status
published
Products (1)
AdguardTeam/AdGuardHome
< 0.107.77
Published
Jun 08, 2026
Tracked Since
Jun 08, 2026