Executive brief
Automad is an open-source content management system. Its password reset functionality leaks information about whether a username or email exists in the system by returning different error messages for valid and invalid accounts. An attacker can enumerate user accounts without authentication, enabling targeted attacks and account discovery.
Technical details
This vulnerability is an information disclosure (user enumeration) in the requestPasswordResetToken function within the Password Reset Endpoint (automad/src/server/Controllers/API/UserController.php). The root cause is observable response discrepancy: when a valid account exists, the endpoint returns one type of error message; when an account does not exist, it returns a different message. The attack vector is network-based and requires no authentication. An unauthenticated attacker can enumerate valid usernames and email addresses by submitting requests to the endpoint and analyzing response differences, facilitating targeted brute-force or phishing attacks. The vulnerability is fixed in version 2.0.0-beta.33 (commit eac0b05) by making the endpoint return identical responses for both valid and invalid accounts.
Affected products
- Automad Automad up to 2.0.0-beta.32
Timeline
- 2026-05-15: disclosed: Issue opened on GitHub describing username/email enumeration vulnerability
- 2026-08-17: advisory: CVE-2026-19965 published
- 2026-08-17: patched: Fix available in version 2.0.0-beta.33 (commit eac0b05)