CVE-2026-27589Disclosure(caddyserver / caddy)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the local caddy admin API (default listen `127.0.0.1:2019`) exposes a state-changing `POST /load` endpoint that replaces the entire running configuration. When origin enforcement is not enabled (`enforce_origin` not configured), the admin endpoint accepts cross-origin requests (e.g., from attacker-controlled web content in a victim browser) and applies an attacker-supplied JSON config. This can change the admin listener settings and alter HTTP server behavior without user intent. Version 2.11.1 contains a fix for the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • caddy

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Products
caddy

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-25: 2Technical Details · 2026-02-25: 202-25
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-27589 Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the local caddy admin API (default listen `127.0.0.1:2019`) exposes a state-… https://www.cve.org/CVERecord?id=CVE-2026-27589

    Post summary

    The snippet notes that CVE‑2026‑27589 involves a local admin API exposure in Caddy before version 2.11.1, but provides no further exploitation or mitigation details.

    00000156
    56.6K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27589: Localhost is a Lie: Caddy Admin API CSRF (CVE-2026-27589) A critical Cross-Site Request Forgery (CSRF) vulnerability in Caddy Web Server's administrative API allows remote attackers to silently overwrite the running configuration of a ... https://cvereports.com/reports/CVE-2026-27589

    Post summary

    The post announces a critical CSRF vulnerability in Caddy Web Server’s admin API that permits attackers to silently overwrite configuration, with no mention of PoC, exploit code, patch, or active exploitation.

    0000041
    32 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcaddyservercaddy---

Explore more