PT-2026-65605 · Cosmos · Cosmos

CVE-2026-49447

·

Published

2026-07-28

·

Updated

2026-07-28

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cosmos versions prior to 0.22.19
Description Cosmos discloses Constellation device metadata to any requester who provides a non-empty Authorization header. The system fails to validate the token provided in the header, stripping the Bearer string but ignoring the resulting value during database queries and permission checks. This allows an unauthenticated attacker to enumerate sensitive information, including device names, user nicknames, internal and VPN IP addresses, node roles, public hostnames, and ports. This issue affects deployments where the Constellation VPN feature is enabled and contains visible devices.
API Endpoints: GET /cosmos/api/constellation/public-devices Vulnerable Parameters or Variables: Authorization
Recommendations Update to version 0.22.19. As a temporary mitigation, restrict access to the GET /cosmos/api/constellation/public-devices endpoint or disable the Constellation VPN feature if it is not required.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49447
GHSA-5FQM-CC34-FCF5

Affected Products

Cosmos