Access Control Bypass in Authelia Authentication Server
CVE-2026-48794

1.3LOW

Key Information:

Vendor

Authelia

Status
Vendor
CVE Published:
19 June 2026

What is CVE-2026-48794?

Authelia, an open-source authentication and authorization server, is vulnerable to a specific access control bypass under certain configurations. Versions 4.36.0 to 4.39.19 can skip critical access control rules if specific conditions are met, including the use of forwarded authorization integration and specific domain structure. In particular, mismatched session domains and permissive access control rules may be exploited, allowing unauthorized access to sensitive resources. Upgrading to version 4.39.20 addresses this issue. Administrators should be aware of the configuration practices that can lead to such vulnerabilities and take necessary steps to ensure robust security.

Affected Version(s)

authelia >= 4.36.0, < 4.39.20

References

CVSS V4

Score:
1.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.