Access Control Bypass in Authelia Authentication Server
CVE-2026-48794
1.3LOW
What is CVE-2026-48794?
Authelia, an open-source authentication and authorization server, is vulnerable to a specific access control bypass under certain configurations. Versions 4.36.0 to 4.39.19 can skip critical access control rules if specific conditions are met, including the use of forwarded authorization integration and specific domain structure. In particular, mismatched session domains and permissive access control rules may be exploited, allowing unauthorized access to sensitive resources. Upgrading to version 4.39.20 addresses this issue. Administrators should be aware of the configuration practices that can lead to such vulnerabilities and take necessary steps to ensure robust security.
Affected Version(s)
authelia >= 4.36.0, < 4.39.20
