New Critical AdGuard Home Flaw Lets Attackers Bypass Authentication
AdGuard Home has released an emergency security hotfix to address a critical vulnerability identified as CVE-2026-32136. This flaw has received a severity rating of 9.8 out of 10 on the Common Vulnerability Scoring System scale.
AdGuard Home has released an emergency security hotfix to address a critical vulnerability identified as CVE-2026-32136. This flaw has received a severity rating of 9.8 out of 10 on the Common Vulnerability Scoring System scale.
The vulnerability allows remote, unauthenticated attackers to bypass the software's login mechanisms completely, gaining full administrative privileges without valid user credentials.
The authentication bypass issue was initially discovered and reported by security researcher mandreko. The AdGuard development team promptly verified the severity of the flaw and submitted it to public vulnerability databases. The team developed and published the 0.107.73 hotfix to mitigate the risk before potential exploitation.
AdGuard Home has released an emergency security hotfix to address a critical vulnerability identified as CVE-2026-32136.
The vulnerability stems from how unpatched versions of AdGuard Home handle network connection upgrade requests. Attackers can exploit this by sending an HTTP/1.1 request that upgrades to HTTP/2 Cleartext (h2c), which bypasses authentication checks and grants administrative control.
The AdGuard team has patched the vulnerability by enforcing strict authentication for requests upgraded from h2c. Users are advised to update AdGuard Home instances to version 0.107.73 or later. Additionally, it is recommended to block public internet access to the management interface and review firewall configurations. Security teams should audit DNS routing rules and access logs for unauthorized changes.
Based on reporting by GBHackers.
