PT-2026-40331 · Unknown · Cleanuparr

CVE-2026-44184

·

Published

2026-05-12

·

Updated

2026-05-12

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cleanuparr versions prior to 2.9.10
Description The global CORS (Cross-Origin Resource Sharing) policy reflects every request Origin and combines it with AllowCredentials(). When the DisableAuthForLocalAddresses setting is enabled, the API authenticates requests based solely on the source IP through the TrustedNetworkAuthenticationHandler() function. This combination allows any website visited by an administrator or a user on a trusted IP to read authenticated API responses cross-origin, which may include the administrator's permanent API key.
Recommendations Update to version 2.9.10.

Exploit

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44184
GHSA-RWPC-36MG-FPVF

Affected Products

Cleanuparr