Cross-site request forgery in Caddy - CVE-2026-27589

 

Cross-site request forgery in Caddy - CVE-2026-27589

Published: April 27, 2026


Vulnerability identifier: #VU128032
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-27589
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to apply an arbitrary configuration and alter server behavior.

The vulnerability exists due to cross-site request forgery in the /load admin endpoint when processing cross-origin requests to the local admin API with origin enforcement disabled. A remote attacker can cause a victim browser to send a specially crafted request to apply an arbitrary configuration and alter server behavior.

User interaction is required, and exploitation requires Caddy to be running with the local admin API enabled and origin enforcement not configured.


Affected software

Caddy

How to mitigate CVE-2026-27589

Install security update from vendor's website.

Caddy - update to 2.11.0

External References

Related Security Bulletins