CVE-2026-41448
AdGuard Home can be tricked into giving full admin access to anyone who can send a specially crafted cookie when the software is started with the --glinet flag. The trick uses a path‑traversal string that lets the attacker read any file on the system.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
AdGuard Home when run with the --glinet flag. No specific versions are listed.
Real-world impact
An attacker can read arbitrary files and gain full administrative control of the device, potentially taking over the network or installing malware.
Why this severity
The CVSS score is high because the vulnerability allows remote unauthenticated attackers to bypass authentication and read any file, giving them full control. The attack requires no user interaction and can be performed over the network.
What to do about it
- ›Avoid using the --glinet flag or disable the glinet feature if possible.
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
NVD description
Timeline
- Jun 8, 2026 · Jun 8, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.