
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27589 is a Cross-Site Request Forgery (CSRF) vulnerability in the Caddy web server's local admin API that allows attackers to replace the entire running configuration via cross-origin requests. It affects all versions of Caddy prior to 2.11.1, specifically the POST /load endpoint on the default admin listener (127.0.0.1:2019). The vulnerability was reported by researcher 1seal and published via GitHub Security Advisory on February 23, 2026, with NVD publication on February 24, 2026. It carries a CVSS v3.1 score of 6.5 (Medium) and a CVSS v4.0 score of 6.9 (Medium) (Github Advisory, Red Hat Bugzilla).
The root cause is improper verification of the source of a communication channel (CWE-940) combined with a classic CSRF weakness (CWE-352). When the enforce_origin option is not configured in the admin endpoint, Caddy's adminLoad.handleLoad function in caddyconfig/load.go (line 73) does not validate the Origin header of incoming requests, allowing cross-origin POST /load requests to be accepted and processed. An attacker can craft a malicious web page that, when visited by a victim whose browser is running locally alongside a Caddy instance, silently issues a POST /load request with an attacker-controlled JSON configuration payload — effectively replacing the entire server configuration without authentication. A public proof-of-concept exploit (poc.zip) was released alongside the advisory, demonstrating the attack by moving the admin listener and altering HTTP response bodies (Github Advisory, Caddy Security Advisory).
Successful exploitation allows an attacker to replace the entire running Caddy configuration with an arbitrary attacker-supplied JSON config, resulting in a high integrity impact with no confidentiality or availability impact directly. Practically, this can enable an attacker to alter HTTP server routing and responses, move the admin listener to a new address (potentially exposing it externally), disable security controls such as TLS or authentication middleware, and redirect or manipulate traffic. The attack requires no authentication or elevated privileges, but does require a victim running Caddy locally to visit an attacker-controlled web page (Github Advisory, Caddy Security Advisory).
A public proof-of-concept exploit (poc.zip) is available and was published alongside the security advisory, demonstrating end-to-end exploitation including admin listener relocation and HTTP response tampering. The CVSS v4.0 exploit maturity is rated as PROOF_OF_CONCEPT. The EPSS score is approximately 0.019% (0.000190), indicating a low but non-zero probability of exploitation in the wild within 30 days. There is no current evidence of active in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog (Github Advisory, Feedly).
127.0.0.1:2019) and enforce_origin is not configured. This is the default configuration for many Caddy deployments.GET http://127.0.0.1:2019/config/ to understand the running configuration structure.cfg['admin']['listen'] = '127.0.0.1:2020') or altering HTTP route handlers to return attacker-controlled responses.POST request to http://127.0.0.1:2019/load with the crafted JSON payload and a spoofed or arbitrary Origin header, using no-cors fetch mode or a form submission to bypass CORS preflight.POST /load request.pwned) (Caddy Security Advisory, Github Advisory).POST requests to http://127.0.0.1:2019/load originating from a browser process with a non-localhost or unexpected Origin header; outbound connections from the Caddy admin port to new or unexpected addresses after a configuration change.POST /load requests with HTTP 200 responses from unexpected origins; log entries indicating the admin listener address changed unexpectedly.127.0.0.1:2019); HTTP server routes or responses changed without administrator action; unexpected modifications to the active Caddy configuration as observed via GET /config/.The primary remediation is to upgrade Caddy to version 2.11.1 or later, which blocks cross-origin requests made with no-cors mode to state-changing admin endpoints by default (Caddy v2.11.1 Release). For deployments that cannot immediately upgrade, enable origin enforcement by adding enforce_origin to the admin endpoint configuration block in the Caddyfile, which restricts the admin API to only accept requests from trusted origins (Github Advisory). Additionally, consider restricting network access to the admin API port (2019) using firewall rules to prevent any unintended local or remote access.
The vulnerability was published by maintainer mholt via GitHub Security Advisory and included as one of several security patches in the Caddy 2.11.1 release, which also addressed five other CVEs (Caddy v2.11.1 Release). Red Hat tracked the issue via Bugzilla and assigned it medium severity (Red Hat Bugzilla). The Solus Linux community newsletter and INCIBE (Spain's national cybersecurity agency) also noted the vulnerability in their advisories. No significant controversy or widespread social media discussion has been observed beyond standard vulnerability tracking channels.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."