Automad < 2.0.0-beta.28 - Unauthenticated Admin Password Hash Disclosure
Automad 2.0.0-alpha.1 to 2.0.0-beta.27 contains a broken access control vulnerability caused by publicly accessible /_api/user-collection/create-first-user endpoint returning full serialized user data, letting unauthenticated attackers retrieve bcrypt password hashes of all administrator accounts, exploit requires the endpoint to remain publicly accessible after initial setup. References: https://github.com/marcantondahmen/automad/security/advisories/GHSA-xm76-r88j-vm3g https://nvd.nist.gov/vuln/detail/CVE-2026-45332 Remediation: Upgrade to version 2.0.0-beta.28 or later.
Used 3k times · domain, subdomain, ipv4