CVE-2026-27586 - Vulnerability Analysis
CriticalCVSS: 9.1Last Updated: February 25, 2026
Caddy - Authentication Bypass
Overview
Caddy < 2.11.1 contains a broken authentication caused by swallowed errors in ClientAuthentication.provision() leading to silent mTLS client certificate authentication failure, letting attackers bypass private CA trust boundary, exploit requires misconfigured or missing CA certificate files.
Severity & Score
Impact
Attackers can bypass mTLS authentication, allowing unauthorized access to the server.
Mitigation
Upgrade to version 2.11.1 or later.
References
Social Media Activity(1 post)
š“ CVE-2026-27586 - Critical (9.1) Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, two swallowed errors in `ClientAuthentication.provision()` cause mTLS client certificate authentication to silently fail open when a CA certificate file is m... š https://www.thehackerwire.com/vulnerability/CVE-2026-27586/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-27586
- Severity
- Critical
- CVSS Score
- 9.1
- Type
- broken_authentication
- Status
- confirmed
- EPSS
- 7.7%
- Social Posts
- 1
CWE
- CWE-755
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N