PT-2026-40330 · Unknown · Cleanuparr

Published

2026-05-12

·

Updated

2026-05-12

·

CVE-2026-44183

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cleanuparr versions prior to 2.9.10
Description TrustedNetworkAuthenticationHandler.ResolveClientIp parses the leftmost entry of the 'X-Forwarded-For' header as the client IP. Because this header is append-only, the leftmost value is controlled by the HTTP client. An unauthenticated remote attacker can send a spoofed local IP in this header to bypass the trusted-network check and gain access as the Cleanuparr administrator.
Recommendations Update to version 2.9.10.

Exploit

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44183

Affected Products

Cleanuparr