Bug 2491901 (CVE-2026-45692)
| Summary: | CVE-2026-45692 github.com/caddyserver/caddy/v2: Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | abuckta, aprice, cmah, dkuc, eshamard, gtanzill, jbuscemi, jdobes, jmitchel, jsamir, jsherril, jvasik, kaycoth, kgaikwad, kshier, mstipich, oezr, orabin, rblanco, rexwhite, rochandr, stcannon, sthirugn, teagle, yguenane |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Caddy, an extensible server platform. A remote administrator with restricted access to specific configuration objects could bypass these limitations. This occurs because the authorization system uses string prefix matching for access paths, while the configuration traversal system interprets array indices numerically. This discrepancy allows an attacker to read and modify unauthorized configuration elements, undermining the principle of least privilege in remote administration.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-06-23 19:02:23 UTC
|