CVE-2026-49446 | azukaar Cosmos Server up to 0.22.18 Token Middleware src/proxy/routerGen.go tokenMiddleware x-cosmos-user improper authentication
A vulnerability was found in azukaar Cosmos Server up to 0.22.18. It has been rated as critical. The impacted element is the function tokenMiddleware of the file src/proxy/routerGen.go of the component Token Middleware. This manipulation of the argument x-cosmos-user causes improper authentication.
This vulnerability is tracked as CVE-2026-49446. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.VulDB Recent EntriesRead More