Junglewise Threat Intelligence

CVE-2026-44058: Netatalk authentication bypass in admin auth user fallback

CVE-2026-44058 · Severity: high · CVSS 7.2 · Published 2026-05-21

Technologies: Netatalk. Vendors: Netatalk.

Executive brief

Netatalk is an open-source implementation of the Apple Filing Protocol (AFP) used to allow Unix-like systems to serve files to macOS clients. A security flaw in the administrative authentication fallback mechanism allows a user with the administrator password to log in as any other user on the system. This could lead to unauthorized access to sensitive user data or full system compromise if an attacker gains administrative credentials.

Technical details

An authentication bypass vulnerability (CWE-287) exists in Netatalk versions 2.2.2 through 4.4.2 due to the way the 'admin auth user' fallback is handled in the AFP configuration. When this feature is enabled, the administrative password can be used to authenticate as any requested user on the system. While the attack requires knowledge of the administrative password (PR:H), it allows for complete impersonation of other users. The issue is resolved in Netatalk version 4.5.0, and a hotfix patch is available for version 4.4.2. Users are advised to avoid setting 'admin auth user' in afp.conf unless strictly necessary.

Affected products

  • Netatalk Netatalk 2.2.2 through 4.4.2

Timeline

  • 2026-05-13: disclosed: Initial disclosure date reported by vendor
  • 2026-05-21: advisory: NVD publication date
  • 2026-05-21: patched: Fixed in version 4.5.0

References

Related threats