What is CVE-2026-49447?
In Cosmos home server platform version 0.22.18, the `GET /cosmos/api/constellation/public-devices` endpoint discloses Constellation device metadata to any requester providing a non-empty Authorization header. This vulnerability allows unauthorized access to device information on the network. Users are advised to update to the latest version and restrict access to this endpoint.
Azərbaycanca: Cosmos home server platformunda (0.22.18 versiyası) `GET /cosmos/api/constellation/public-devices` endpoint-i Authorization header-da hər hansı boş olmayan dəyər göndərən istifadəçiyə Constellation cihaz metadata-sını açıqlayır. Bu zəiflik istənilən şəxsin şəbəkədəki cihaz məlumatlarına icazəsiz giriş əldə etməsinə səbəb ola bilər. İstifadəçilərə ən son versiyaya yeniləmə və bu endpoint-ə girişi məhdudlaşdırma tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
In which version of the Cosmos home server platform was CVE-2026-49447 discovered?
This vulnerability was discovered in version 0.22.18 of the Cosmos home server platform.
How can unauthorized access be obtained using CVE-2026-49447?
By sending a request with a non-empty Authorization header to the `GET /cosmos/api/constellation/public-devices` endpoint, unauthorized access to Constellation device metadata can be obtained.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.