User Impersonation Vulnerability in Cosmos Server by Azukaar
CVE-2026-49446
6.1MEDIUM
What is CVE-2026-49446?
Cosmos Server by Azukaar allows users to self-host home servers while acting as a secure gateway. A security flaw prior to version 0.22.19 in the tokenMiddleware component can let attackers exploit forward-auth headers. When an upstream application trusts the x-cosmos-user header, an attacker with a valid x-cstln-auth API key can impersonate users, bypassing critical security measures including JWT, passwords, multi-factor authentication, and admin-only access. This vulnerability puts sensitive data at risk and enables unauthorized access to the application. Users are strongly encouraged to update to version 0.22.19 to mitigate this risk.
Affected Version(s)
Cosmos-Server < 0.22.19
