7.5
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Description
Automad is a flat-file content management system and template engine. From 2.0.0-alpha.1 to 2.0.0-beta.27, a Broken Access Control vulnerability allows an unauthenticated attacker to retrieve the bcrypt password hash of every administrator account with a single POST request. The /_api/user-collection/create-first-user setup endpoint remains publicly accessible once initial configuration is complete and returns full serialized user data in the JSON response body. This vulnerability is fixed in 2.0.0-beta.28.
Basic Information
ID
CVE-2026-45332
Source
GitHub_M
Published
May 28, 2026 at 18:22
Affected Product
Vendor
marcantondahmen
Product
automad
Version
>= 2.0.0-alpha.1, < 2.0.0-beta.28
Affected Versions
marcantondahmen automad >= 2.0.0-alpha.1, < 2.0.0-beta.28