CVE-2026-32136

AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.73, an unauthenticated remote attacker can bypass all authentication in AdGuardHome by sending an HTTP/1.1 request that requests an upgrade to HTTP/2 cleartext (h2c). Once the upgrade is accepted, the resulting HTTP/2 connection is handled by the inner mux, which has no authentication middleware attached. All subsequent HTTP/2 requests on that connection are processed as fully authenticated, regardless of whether any credentials were provided. This vulnerability is fixed in 0.107.73.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:adguard:adguardhome:*:*:*:*:*:*:*:*

History

13 Mar 2026, 20:19

Type Values Removed Values Added
CWE NVD-CWE-noinfo
First Time Adguard
Adguard adguardhome
Summary
  • (es) AdGuard Home es un software a nivel de red para bloquear anuncios y rastreo. Antes de la versión 0.107.73, un atacante remoto no autenticado puede eludir toda la autenticación en AdGuardHome enviando una solicitud HTTP/1.1 que solicita una actualización a HTTP/2 en texto claro (h2c). Una vez que se acepta la actualización, la conexión HTTP/2 resultante es manejada por el multiplexor interno, que no tiene ningún middleware de autenticación adjunto. Todas las solicitudes HTTP/2 posteriores en esa conexión se procesan como completamente autenticadas, independientemente de si se proporcionaron credenciales. Esta vulnerabilidad se corrige en la versión 0.107.73.
CPE cpe:2.3:a:adguard:adguardhome:*:*:*:*:*:*:*:*
References () https://github.com/AdguardTeam/AdGuardHome/security/advisories/GHSA-5fg6-wrq4-w5gh - () https://github.com/AdguardTeam/AdGuardHome/security/advisories/GHSA-5fg6-wrq4-w5gh - Exploit, Vendor Advisory, Mitigation

11 Mar 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-11 22:16

Updated : 2026-03-13 20:19


NVD link : CVE-2026-32136

Mitre link : CVE-2026-32136

CVE.ORG link : CVE-2026-32136


JSON object : View

Products Affected

adguard

  • adguardhome
CWE
CWE-287

Improper Authentication

NVD-CWE-noinfo