CVE-2026-32136 is a critical improper authentication vulnerability in AdGuard Home affecting versions prior to 0.107.73. The flaw arises in handling of HTTP/1.1 requests that request an upgrade to HTTP/2 cleartext (h2c). After the upgrade is accepted, the resulting HTTP/2 connection is routed to an internal mux that does not have the authentication middleware attached. Because authentication is only enforced on the initial HTTP/1.1 upgrade request path and not on the post-upgrade HTTP/2 request handling path, all subsequent HTTP/2 requests sent over that upgraded connection are treated as fully authenticated even when no valid credentials were supplied. This enables a remote unauthenticated attacker to bypass all authentication controls protecting administrative functionality.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small proof-of-concept exploit for CVE-2026-32136 affecting AdGuard Home before 0.107.73. It contains one Python exploit script and one README. The Python script manually opens a TCP socket to the target, sends an HTTP/1.1 request to /login.html with Connection: Upgrade and Upgrade: h2c headers, verifies that the server responds with HTTP/1.1 101 Switching Protocols, then initializes an HTTP/2 client using the python-h2 library. After the upgrade succeeds, it sends a new HTTP/2 GET request on a fresh stream to a user-supplied path, defaulting to /control/filtering/status, and prints the response body. The exploit capability is an authentication bypass: it abuses the server's incorrect placement of auth middleware around h2c handling so that subsequent HTTP/2 streams on the upgraded connection reach protected /control/* endpoints without authentication. The code is straightforward, has no post-exploitation payload, and is intended to retrieve sensitive administrative data such as filtering rules, status, clients, DNS info, or query logs. Repository structure is minimal and purpose-built: README documents the vulnerability, affected versions, usage, example endpoints, and mitigation; the Python file is the sole executable entry point.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A prior critical AdGuard Home authentication bypass involving HTTP/2 cleartext (h2c) upgrade handling, mentioned for comparison with CVE-2026-41448.
Authentication bypass in AdGuard Home via HTTP/1.1 to HTTP/2 cleartext (h2c) upgrade, where the post-upgrade HTTP/2 connection is handled without authentication middleware, causing subsequent requests to be treated as authenticated.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.