Path Traversal Vulnerability in Caddy Server on Windows
CVE-2026-52844

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
23 June 2026

What is CVE-2026-52844?

An issue in Caddy Server prior to version 2.11.4 on Windows allows unauthenticated remote clients to bypass path-scoped authentication and authorization controls. Specifically, the server misinterprets path matchers, leading to the potential exposure of secured files like /private/secret.txt. This can compromise sensitive data if not resolved. The vulnerability has been addressed in version 2.11.4, and users are strongly encouraged to upgrade to eliminate this security risk.

Affected Version(s)

caddy < 2.11.4

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.