CVE-2026-45332

Source
https://cve.org/CVERecord?id=CVE-2026-45332
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45332.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-45332
Aliases
Published
2026-05-28T18:22:11Z
Modified
2026-08-12T03:51:09Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Automad Broken Access Control: unauthenticated exposure of administrator bcrypt password hashes and TOTP secrets via public API endpoint
Details

Automad is a flat-file content management system and template engine. From 2.0.0-alpha.1 to 2.0.0-beta.27, a Broken Access Control vulnerability allows an unauthenticated attacker to retrieve the bcrypt password hash of every administrator account with a single POST request. The /_api/user-collection/create-first-user setup endpoint remains publicly accessible once initial configuration is complete and returns full serialized user data in the JSON response body. This vulnerability is fixed in 2.0.0-beta.28.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-200",
        "CWE-306"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45332.json"
}
References

Affected packages

Git / github.com/marcantondahmen/automad

Affected ranges

Type
GIT
Repo
https://github.com/marcantondahmen/automad
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "2.0.0-alpha.1"
        },
        {
            "fixed": "2.0.0-beta.28"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

2.*
2.0.0-alpha.1
2.0.0-alpha.10
2.0.0-alpha.11
2.0.0-alpha.12
2.0.0-alpha.13
2.0.0-alpha.14
2.0.0-alpha.15
2.0.0-alpha.16
2.0.0-alpha.17
2.0.0-alpha.18
2.0.0-alpha.19
2.0.0-alpha.2
2.0.0-alpha.20
2.0.0-alpha.21
2.0.0-alpha.22
2.0.0-alpha.23
2.0.0-alpha.24
2.0.0-alpha.25
2.0.0-alpha.26
2.0.0-alpha.27
2.0.0-alpha.28
2.0.0-alpha.29
2.0.0-alpha.3
2.0.0-alpha.30
2.0.0-alpha.31
2.0.0-alpha.32
2.0.0-alpha.33
2.0.0-alpha.34
2.0.0-alpha.35
2.0.0-alpha.36
2.0.0-alpha.37
2.0.0-alpha.38
2.0.0-alpha.39
2.0.0-alpha.4
2.0.0-alpha.40
2.0.0-alpha.41
2.0.0-alpha.42
2.0.0-alpha.43
2.0.0-alpha.44
2.0.0-alpha.45
2.0.0-alpha.46
2.0.0-alpha.47
2.0.0-alpha.48
2.0.0-alpha.49
2.0.0-alpha.5
2.0.0-alpha.50
2.0.0-alpha.51
2.0.0-alpha.52
2.0.0-alpha.53
2.0.0-alpha.6
2.0.0-alpha.7
2.0.0-alpha.8
2.0.0-alpha.9
2.0.0-beta.1
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.15
2.0.0-beta.16
2.0.0-beta.17
2.0.0-beta.18
2.0.0-beta.19
2.0.0-beta.2
2.0.0-beta.20
2.0.0-beta.21
2.0.0-beta.22
2.0.0-beta.23
2.0.0-beta.24
2.0.0-beta.25
2.0.0-beta.26
2.0.0-beta.27
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45332.json"