CVE-2026-41448 Details
Description
AdGuard Home, when started with the --glinet flag, contains an authentication bypass vulnerability that allows unauthenticated attackers to gain full admin access by supplying a path traversal sequence in the Admin-Token cookie, exploiting unsanitized string concatenation in the token file path construction within the authglinet middleware. Attackers can craft a request with a traversal payload in the Admin-Token header to redirect file reads to arbitrary paths.
An authentication bypass vulnerability has been identified in AdGuard Home versions prior to 0.107.77, when the application is started with the --glinet flag. This vulnerability allows unauthenticated attackers to gain full administrative access by injecting a path traversal sequence into the Admin-Token cookie. The issue arises from unsanitized string concatenation in the token file path construction within the authglinet middleware, enabling attackers to redirect file reads to arbitrary paths.
Users can upgrade to AdGuard Home version 0.107.77 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 8, 2026CISA-ADP
Assessed Jun 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/AdguardTeam/AdGuardHome/releases/tag/v0.107.77 | [email protected] | Release NotesVendor |
| https://www.vulncheck.com/advisories/adguard-home-authentication-bypass-via-path-traversal-in-admin-token-cookie | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| AdGuard Home | < 0.107.77 (semver) |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 8, 2026 | New CVE Received | [email protected] |
Volerion