Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-54907— Caddy Proxy Manager: Registrations enabled by default allows creating users with "user" permission

Quick assessment

Affected
fuomag9 caddy-proxy-manager
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Caddy Proxy Manager 是一个用于管理 Caddy 服务器反向代理和证书的 Web 界面。在 1.5.1 版本之前,Caddy Proxy Manager 默认启用电子邮件和密码自助注册功能,端点为 ,使得未经身份验证的远程用户可以创建具有“user”角色的活跃账户,且无需管理员审批。由于“user”角色无法查看或修改代理数据,因此该问题的直接影响仅限于非授权地创建低权限账户。修复后的配置(位于 和 中)要求在认证库的 控制允许注册之前,必须显式设置 。该问题已在 1.5.1 版本中修复。

CVSS 5.3 · Medium EPSS 0.17% · P7

Affected Version Matrix 1

VendorProduct Version RangeStatus
fuomag9 caddy-proxy-manager < 1.5.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-54907

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Caddy Proxy Manager: Registrations enabled by default allows creating users with "user" permission
Source: CVE Program / CVE List V5
Vulnerability Description
Caddy Proxy Manager is a web interface for managing Caddy Server reverse proxies and certificates. Prior to 1.5.1, Caddy Proxy Manager enables email and password self-registration by default at /api/auth/sign-up/email, allowing an unauthenticated remote actor to create an active account with the user role without administrator approval. The user role cannot view or modify proxy data, so the direct impact is limited to unauthorized creation of low-privilege accounts. The fixed configuration in src/lib/config.ts and src/lib/auth-server.ts requires AUTH_ALLOW_SELF_REGISTRATION=true before the authentication library's disableSignUp control permits sign-up. This issue is fixed in version 1.5.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
不安全的默认资源初始化
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
fuomag9 caddy-proxy-manager < 1.5.1 -

II. Public POCs for CVE-2026-54907

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-54907

登录查看更多情报信息。

Patches & Fixes for CVE-2026-54907 (1)

Vendor Advisories for CVE-2026-54907 (1)

Vendor Pages for CVE-2026-54907 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-54907

No comments yet


Leave a comment