# CVE-2026-27586

## Summary

- **CVE ID:** CVE-2026-27586
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P)
- **CWE:** CWE-755
- **Published:** Feb 24, 2026
- **Last Modified:** Mar 12, 2026

## Description

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, two swallowed errors in `ClientAuthentication.provision()` cause mTLS client certificate authentication to silently fail open when a CA certificate file is missing, unreadable, or malformed. The server starts without error but accepts any client certificate signed by any system-trusted CA, completely bypassing the intended private CA trust boundary. Any deployment using `trusted_ca_cert_file` or `trusted_ca_certs_pem_files` for mTLS will silently degrade to accepting any system-trusted client certificate if the CA file becomes unavailable. This can happen due to a typo in the path, file rotation, corruption, or permission changes. The server gives no indication that mTLS is misconfigured. Version 2.11.1 fixes the vulnerability.

## Affected Products

- caddyserver — caddy (< 2.11.1)

## References

- [CNA](https://github.com/caddyserver/caddy/security/advisories/GHSA-hffm-g8v7-wrv7)
- [CNA](https://gist.github.com/moscowchill/9566c79c76c0b64c57f8bd0716f97c48)
- [CNA](https://github.com/caddyserver/caddy/releases/tag/v2.11.1)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.27%
- **EPSS Percentile:** 19.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._