PT-2026-47346 · Adguard · Adguardhome

·

CVE-2026-41448

·

Published

2026-06-08

·

Updated

2026-06-10

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions AdGuard Home versions prior to 0.107.77
Description When started with the --glinet flag, the software contains an authentication bypass that allows unauthenticated attackers to gain full administrative access. This occurs due to unsanitized string concatenation in the token file path construction within the authglinet middleware. Attackers can use a path traversal sequence in the Admin-Token cookie to redirect file reads to arbitrary paths.
Over 122,000 potentially affected devices have been identified worldwide.
Recommendations Update to version 0.107.77 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41448

Affected Products

Adguardhome