PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2026-45332

7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.
Description

Automad is a flat-file content management system and template engine. From 2.0.0-alpha.1 to 2.0.0-beta.27, a Broken Access Control vulnerability allows an unauthenticated attacker to retrieve the bcrypt password hash of every administrator account with a single POST request. The /_api/user-collection/create-first-user setup endpoint remains publicly accessible once initial configuration is complete and returns full serialized user data in the JSON response body. This vulnerability is fixed in 2.0.0-beta.28.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
automad
Updated Sep 18, 2026View on NVD →
S4E scanner
highMisconfiguration~10 seconds

Automad < 2.0.0-beta.28 - Unauthenticated Admin Password Hash Disclosure

Automad 2.0.0-alpha.1 to 2.0.0-beta.27 contains a broken access control vulnerability caused by publicly accessible /_api/user-collection/create-first-user endpoint returning full serialized user data, letting unauthenticated attackers retrieve bcrypt password hashes of all administrator accounts, exploit requires the endpoint to remain publicly accessible after initial setup. References: https://github.com/marcantondahmen/automad/security/advisories/GHSA-xm76-r88j-vm3g https://nvd.nist.gov/vuln/detail/CVE-2026-45332 Remediation: Upgrade to version 2.0.0-beta.28 or later.

Used 3k times · domain, subdomain, ipv4

CVE history: automad

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →