Description
Caddy Proxy Manager is a web interface for managing Caddy Server reverse proxies and certificates. Prior to 1.5.1, Caddy Proxy Manager enables email and password self-registration by default at /api/auth/sign-up/email, allowing an unauthenticated remote actor to create an active account with the user role without administrator approval. The user role cannot view or modify proxy data, so the direct impact is limited to unauthorized creation of low-privilege accounts. The fixed configuration in src/lib/config.ts and src/lib/auth-server.ts requires AUTH_ALLOW_SELF_REGISTRATION=true before the authentication library's disableSignUp control permits sign-up. This issue is fixed in version 1.5.1.
Published: 2026-09-17
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized creation of low‑privilege user accounts via self‑registration
Action: Apply patch
AI Analysis

Impact

Caddy Proxy Manager enabled email and password self‑registration by default in its sign‑up API, allowing any unauthenticated remote actor to create an account with the default "user" role. The "user" role has no privileges to view or edit proxy configurations, so the direct impact is limited to the ability to create low‑privilege accounts but it can serve as an entry point for further attacks or testing. The vulnerability is a configuration flaw that permits account creation without administrator approval.

Affected Systems

The issue affects the Caddy Proxy Manager application from vendor fuomag9. Any installation running an unpatched version older than 1.5.1 is susceptible. System administrators should verify that the product version is at least 1.5.1 or that the configuration has been hardened to disable self‑registration.

Risk and Exploitability

The CVSS score of 5.3 reflects a moderate impact and a low complexity of exploitation. The EPSS score of less than 1% indicates a very low current probability of exploitation. The vulnerability is not listed in CISA KEV and is not a known widely‑exploited weakness. The attack vector is likely remote and unauthenticated, requiring only HTTP access to the sign‑up endpoint.

Generated by OpenCVE AI on September 19, 2026 at 02:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Caddy Proxy Manager version 1.5.1 or later where self‑registration is disabled by default and requires the AUTH_ALLOW_SELF_REGISTRATION environment variable to be set to true before registration is enabled.
  • If upgrading is not possible, modify the configuration by setting AUTH_ALLOW_SELF_REGISTRATION=false or patching the auth‑server to prevent the sign‑up API from creating accounts.
  • Audit logs for unexpected account creation and monitor for attempts to exploit the sign‑up endpoint.

Generated by OpenCVE AI on September 19, 2026 at 02:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Fuomag9
Fuomag9 caddy-proxy-manager
Vendors & Products Fuomag9
Fuomag9 caddy-proxy-manager
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Caddy Proxy Manager is a web interface for managing Caddy Server reverse proxies and certificates. Prior to 1.5.1, Caddy Proxy Manager enables email and password self-registration by default at /api/auth/sign-up/email, allowing an unauthenticated remote actor to create an active account with the user role without administrator approval. The user role cannot view or modify proxy data, so the direct impact is limited to unauthorized creation of low-privilege accounts. The fixed configuration in src/lib/config.ts and src/lib/auth-server.ts requires AUTH_ALLOW_SELF_REGISTRATION=true before the authentication library's disableSignUp control permits sign-up. This issue is fixed in version 1.5.1.
Title Caddy Proxy Manager: Registrations enabled by default allows creating users with "user" permission
Weaknesses CWE-1188
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Fuomag9 Caddy-proxy-manager
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T20:06:13.644Z

Reserved: 2026-06-16T13:49:33.556Z

Link: CVE-2026-54907

cve-icon Vulnrichment

Updated: 2026-09-18T20:06:10.041Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T21:17:17.647

Modified: 2026-09-23T18:12:04.247

Link: CVE-2026-54907

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T02:45:16Z

Weaknesses
  • CWE-1188

    Initialization of a Resource with an Insecure Default