User Impersonation Vulnerability in Cosmos Server by Azukaar
CVE-2026-49446

6.1MEDIUM

Key Information:

Vendor

Azukaar

Vendor
CVE Published:
15 September 2026

What is CVE-2026-49446?

Cosmos Server by Azukaar allows users to self-host home servers while acting as a secure gateway. A security flaw prior to version 0.22.19 in the tokenMiddleware component can let attackers exploit forward-auth headers. When an upstream application trusts the x-cosmos-user header, an attacker with a valid x-cstln-auth API key can impersonate users, bypassing critical security measures including JWT, passwords, multi-factor authentication, and admin-only access. This vulnerability puts sensitive data at risk and enables unauthorized access to the application. Users are strongly encouraged to update to version 0.22.19 to mitigate this risk.

Affected Version(s)

Cosmos-Server < 0.22.19

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.