PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Misconfiguration·Updated Aug 14, 2026

Automad < 2.0.0-beta.28 - Unauthenticated Admin Password Hash Disclosure

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
3k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.
Description

Automad is a flat-file content management system and template engine. From 2.0.0-alpha.1 to 2.0.0-beta.27, a Broken Access Control vulnerability allows an unauthenticated attacker to retrieve the bcrypt password hash of every administrator account with a single POST request. The /_api/user-collection/create-first-user setup endpoint remains publicly accessible once initial configuration is complete and returns full serialized user data in the JSON response body. This vulnerability is fixed in 2.0.0-beta.28.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
automadby marcantondahmen
>= 2.0.0-alpha.1, < 2.0.0-beta.28
Updated Sep 18, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

Automad < 2.0.0-beta.28 - Unauthenticated Admin Password Hash Disclosure CVE-2026-45332 Scanner | S4E