CVE 7.5 HIGH

Automad Broken Access Control: unauthenticated exposure of administrator bcrypt password hashes and TOTP secrets via public API endpoint_CVE-2026-45332

7.5 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

Automad is a flat-file content management system and template engine. From 2.0.0-alpha.1 to 2.0.0-beta.27, a Broken Access Control vulnerability allows an unauthenticated attacker to retrieve the bcrypt password hash of every administrator account with a single POST request. The /_api/user-collection/create-first-user setup endpoint remains publicly accessible once initial configuration is complete and returns full serialized user data in the JSON response body. This vulnerability is fixed in 2.0.0-beta.28.

Basic Information

ID CVE-2026-45332
Source GitHub_M
Published May 28, 2026 at 18:22

Affected Product

Vendor marcantondahmen
Product automad
Version >= 2.0.0-alpha.1, < 2.0.0-beta.28
Affected Versions marcantondahmen automad >= 2.0.0-alpha.1, < 2.0.0-beta.28

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.