CVE-2026-48794
### Impact **CVSSv4 Baseline Score:** Low 2.4 **CVSSv4 Weighted Score:** Low 1.3 The full CVSSv4 Vector for this vulnerability is: > CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:P/CR:H/IR:L/AR:L/MAV:N/MAC:H/MAT:P/MPR:L/MVC:L/MVI:N/MVA:N/MSC:L/MSI:N/MSA:N/S:N/AU:Y/R:U/V:D/RE:L/U:Amber **CVSSv3.1 Baseline Score:** Low 3.1 **CVSSv3.1 Overall Score:** Low 3.4 The full CVSSv3.1 Vector equivalent for this vulnerability is: > CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C/CR:H/IR:L/AR:L/MAV:N/MAC:H/MPR:L/MUI:X/MS:U/MC:L/MI:N/MA:N The weighted severity rating is a result of no indication this is currently being exploited being available at the time of the publish date, in addition to the fact it's unlikely that it is being exploited currently. The vectors have been picked based on the scenario most likely to exist in real configurations. In addition to the weighting our assessment considers the fact the configuration scenario required for this vulnerability to be exploited is highly unlikely and an attacker is unlikely in most scenarios to be able to determine if the exploit is available and if it was successful except in rare situations. Though the visibility to the attacker was not reflected in our assessment. ### Summary Due to lack of canonicalization of domains in very specific edge cases an access control rule may be skipped when it should match a request. ### Details This attack vector must be executed in a highly specific scenario which we do not believe any user would find themselves in. In an abundance of caution we are issuing this advisory and would appreciate any users who find this configuration report it to us with both the access control section, and sessions section so that we can best advise the community of the actual impact. The specific conditions that could lead to a security issue for vulnerability are as follows: 1. The specific target resource of the attack must be using the forwarded authorization in
Properties
- ghsa_id
- GHSA-j748-h363-wqj8
- summary
- Authelia has an Edge Case Access Control Rule Mismatch
- severity
- low
- epss_score
- 0.00283
- cve_id
- CVE-2026-48794
- is_ghsa_only
- false
- ghsa_published
- 2026-06-26T22:32:21Z
- source_url
- https://github.com/advisories/GHSA-j748-h363-wqj8
- epss_percentile
- 0.20524
- ghsa_updated
- 2026-06-26T22:32:22Z
Related Entities (6)
ENRICHED_BY (1)
HAS_WEAKNESS (2)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
Explore deeper with Ninja Signal's threat intelligence graph