


Perceptive Security
SOC/SIEM Consultancy

Automad is a flat-file content management system and template engine. From 2.0.0-alpha.1 to 2.0.0-beta.27, a Broken Access Control vulnerability allows an unaut…
Published:
27 mei 2026 om 22:00:00
Alert date:
28 mei 2026 om 20:05:25
Source:
nvd.nist.gov
Web Technologies, Identity & Access
Automad content management system versions 2.0.0-alpha.1 to 2.0.0-beta.27 contain a Broken Access Control vulnerability. The flaw allows unauthenticated attackers to retrieve bcrypt password hashes of all administrator accounts through a single POST request. The vulnerable endpoint /_api/user-collection/create-first-user remains publicly accessible after initial setup and returns full user data in JSON responses. This represents a critical security flaw that could lead to credential compromise. The vulnerability has been patched in version 2.0.0-beta.28.
Technical details
Mitigation steps:
Affected products:
Automad
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-45332
https://github.com/marcantondahmen/automad/security/advisories/GHSA-xm76-r88j-vm3g
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
