Junglewise Threat Intelligence

CVE-2026-48794: Authelia incorrect authorization via improper domain canonicalization

CVE-2026-48794 · Severity: medium · CVSS 4 · Published 2026-06-19

Technologies: github.com/authelia/authelia/v4 (Go), github.com/authelia/authelia (Go). Vendors: Go.

Executive brief

Authelia, an open-source authentication and authorization server, contains a flaw where specific access control rules might be bypassed under rare conditions. In certain configurations involving wildcard domains and mixed-case URLs, a user might be granted access based on a less restrictive rule than intended, such as requiring only one-factor authentication instead of two-factor. This could lead to unauthorized access to protected resources if an attacker identifies a vulnerable configuration.

Technical details

An access control rule mismatch exists in Authelia due to a lack of domain canonicalization (CWE-178) when processing forwarded authorization requests. The vulnerability occurs when a request uses mixed-case characters in a specific domain segment (e.g., a.B.example.com) and the configuration contains overlapping wildcard rules ordered from most specific to least specific. If the proxy does not normalize the host header before forwarding to Authelia, the more specific rule may be skipped, causing the engine to evaluate a subsequent, potentially more permissive rule (CWE-863). This requires a highly specific configuration where the session domain is two segments shorter than the requested domain and the integration is not Envoy ExtAuthz. The issue is fixed in version 4.39.20.

Affected products

  • Authelia Authelia >= 4.36.0, <= 4.39.19

Timeline

  • 2026-05-26: disclosed
  • 2026-06-19: advisory: NVD publication date
  • 2026-06-26: patched: GitHub Advisory published/updated with patch information

References

Related threats