Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization
Published Jun 23, 2026
5.4
MEDIUMCVSS 3.1
EPSS 0.24%
Description
Caddy is an extensible server platform that uses TLS by default. From 2.4.0 until 2.11.3, the authorization layer and the /config traversal layer do not agree on what object the path refers to. In this case, a path authorized for one config object is accepted, but then resolves to a different config object during traversal. This happens because the authorization layer uses string prefix matching and the /config traversal layer parses array indices numerically using strconv.Atoi(). This vulnerability is fixed in 2.11.3.
Affected products
-
Affected
- ≥ 2.4.0, < 2.11.3
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Caddyserver | Caddy | unknown | Affected
|
- ≥ 2.4.0 · < 2.11.3
No data.
Red Hat Hardened Images
caddy
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | caddy | Not affected | n/a |
github.com/caddyserver/caddy/v2
Go
Introduced 2.4.0 Fixed 2.11.3
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/caddyserver/caddy/v2 | 2.4.0 | 2.11.3 |
Remediation
Red Hat statement
This Moderate-impact flaw in Caddy's remote administration API, which allows an authorization bypass due to differing interpretations of array indices, does not affect Red Hat products. The vulnerable code is not present in Red Hat's supported offerings.
Red Hat mitigation
Mitigation for this issue is not required for Red Hat products, as the vulnerable code is not present.
References (7)
- https://access.redhat.com/security/cve/CVE-2026-45692 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2491901 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38559 Advisory
- https://github.com/advisories/GHSA-x5w9-xh9r-mvfc Advisory
- https://github.com/caddyserver/caddy/security/advisories/GHSA-x5w9-xh9r-mvfc exploitx_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-45692
- https://www.cve.org/CVERecord?id=CVE-2026-45692
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-45692 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2491901 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38559 | Advisory | |
| https://github.com/advisories/GHSA-x5w9-xh9r-mvfc | Advisory | |
| https://github.com/caddyserver/caddy/security/advisories/GHSA-x5w9-xh9r-mvfc | exploitx_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-45692 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-45692 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub