CVE-2026-44058: Authentication bypass via admin auth user
Published May 21, 2026
·Updated
An authentication bypass vulnerability in Netatalk 2.2.2 through 4.4.2 allows a remote privileged user to authenticate as an arbitrary user via the admin auth user mechanism.
Affected Software
1 affected component
Netatalk Netatalk>=2.2.2<=4.4.2
Event History
May 21, 2026
CVE Published
via MITRE·07:34 AM
Data Sourced
via MITRE·07:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-44058?
CVE-2026-44058 has a high severity rating of 7.2.
2
How do I fix CVE-2026-44058?
To fix CVE-2026-44058, update Netatalk to version 4.5.0 or later.
3
What is the impact of CVE-2026-44058?
CVE-2026-44058 allows a remote privileged user to bypass authentication and access the system as any user.
4
Which versions of Netatalk are affected by CVE-2026-44058?
CVE-2026-44058 affects Netatalk versions 2.2.2 through 4.4.2.
5
Is there a workaround for CVE-2026-44058?
There is no official workaround for CVE-2026-44058; upgrading to a fixed version is recommended.