Local Authentication Bypass in Neotoma by Mark M. Hendrickson
CVE-2026-45577

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
29 May 2026

What is CVE-2026-45577?

Neotoma versions from 0.6.0 up to but not including 0.11.1 exhibit a security flaw where public reverse-proxied requests can be misconstrued as local requests, specifically when transmitted through a loopback socket in the absence of a Bearer token. This oversight in the REST authorization middleware can lead to unauthorized access, allowing unauthenticated users to interact with the hosted Inspector and related APIs, thus undermining the intended access controls. The issue is remediated in version 0.11.1.

Affected Version(s)

neotoma >= 0.6.0, < 0.11.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.