Back

MEDIUM

Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization

Published Jun 23, 2026

Description

Caddy is an extensible server platform that uses TLS by default. From 2.4.0 until 2.11.3, the authorization layer and the /config traversal layer do not agree on what object the path refers to. In this case, a path authorized for one config object is accepted, but then resolves to a different config object during traversal. This happens because the authorization layer uses string prefix matching and the /config traversal layer parses array indices numerically using strconv.Atoi(). This vulnerability is fixed in 2.11.3.

Affected products

Remediation

Red Hat statement

This Moderate-impact flaw in Caddy's remote administration API, which allows an authorization bypass due to differing interpretations of array indices, does not affect Red Hat products. The vulnerable code is not present in Red Hat's supported offerings.

Red Hat mitigation

Mitigation for this issue is not required for Red Hat products, as the vulnerable code is not present.

References (7)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Jun 23, 2026
Updated Jun 26, 2026
Reserved May 13, 2026

CISA Vulnrichment

Updated Jun 26, 2026

NVD

Status Modified
Modified Jun 26, 2026

Red Hat

Severity Moderate
Public date Jun 23, 2026
Bugzilla 2491901

ENISA EUVD

Assigner GitHub_M
Published Jun 23, 2026
Updated Jun 26, 2026