CVE-2026-49446Medium· 6.1▾ TwilightPoC availableCosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. Prior to 0.22.19, tokenMiddleware in src/proxy/routerGen.go can return through the Constellation tu…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 33.6 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Exploit / PoC code exists
0.3%
Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. Prior to 0.22.19, tokenMiddleware in src/proxy/routerGen.go can return through the Constellation tunnel bypass before removing x-cosmos-user, x-cosmos-role, x-cosmos-user-role, and x-cosmos-mfa headers and before invoking AdminOnlyWithRedirect. An attacker with a valid x-cstln-auth API key for an enrolled device who reaches Cosmos through the Constellation Nebula tunnel can supply a chosen x-cosmos-user value to a route with AuthEnabled enabled when the upstream application trusts that forward-auth header. The request can bypass Cosmos JWT, password, MFA, and AdminOnly checks, allowing user impersonation and admin-tier reads or writes exposed by the proxied application. This issue is fixed in version 0.22.19.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/azukaar/cosmos-server <= 0.22.18Patched in:
github.com/azukaar/cosmos-server 0.22.19Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-49447Medium· 5.3Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens
CVE-2026-61833High· 8.1zot is a container image and artifact registry based on the Open Container Initiative Distribution Specification
CVE-2026-58704High· 8.8In Cellular Modem, there is a possible permission bypass due to a logic error in the code
CVE-2026-90858High· 7.3A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578
CVE-2026-2015Medium· 6.3A weakness has been identified in Portabilis i-Educar up to 2.10
CVE-2026-84600Medium· 5.4An authorization issue was addressed with improved state management