PT-2026-95105 · Unknown · Caddy-Proxy-Manager
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Caddy Proxy Manager versions prior to 1.5.1
Description
Caddy Proxy Manager allows unauthenticated remote actors to create active accounts with the user role without administrator approval. This occurs because email and password self-registration is enabled by default at the '/api/auth/sign-up/email' endpoint. The impact is limited to the unauthorized creation of low-privilege accounts, as the user role cannot view or modify proxy data.
Recommendations
Update to version 1.5.1.
Set the
AUTH ALLOW SELF REGISTRATION variable to false to disable self-registration.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Caddy-Proxy-Manager