Automad is a flat-file content management system and template engine. From 2.0.0-alpha.1 to 2.0.0-beta.27, a Broken Access Control vulnerability allows an unauthenticated attacker to retrieve the bcrypt password hash of every administrator account with a single POST request. The /_api/user-collection/create-first-user setup endpoint remains publicly accessible once initial configuration is complete and returns full serialized user data in the JSON response body. This vulnerability is fixed in 2.0.0-beta.28.
History

Fri, 29 May 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Marcantondahmen
Marcantondahmen automad
Vendors & Products Marcantondahmen
Marcantondahmen automad

Thu, 28 May 2026 19:00:00 +0000

Type Values Removed Values Added
Description Automad is a flat-file content management system and template engine. From 2.0.0-alpha.1 to 2.0.0-beta.27, a Broken Access Control vulnerability allows an unauthenticated attacker to retrieve the bcrypt password hash of every administrator account with a single POST request. The /_api/user-collection/create-first-user setup endpoint remains publicly accessible once initial configuration is complete and returns full serialized user data in the JSON response body. This vulnerability is fixed in 2.0.0-beta.28.
Title Automad Broken Access Control: unauthenticated exposure of administrator bcrypt password hashes and TOTP secrets via public API endpoint
Weaknesses CWE-200
CWE-306
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2026-05-28T18:22:11.883Z

Updated: 2026-05-28T18:22:11.883Z

Reserved: 2026-05-11T20:50:30.540Z

Link: CVE-2026-45332

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-28T19:16:39.133

Modified: 2026-05-28T19:16:39.133

Link: CVE-2026-45332

cve-icon Redhat

No data.