CVE-2026-56262

MEDIUM

Crawl4AI - Unauthenticated Access to Monitor Endpoints via Docker API Server

Title source: cna
STIX 2.1

Description

Crawl4AI before 0.8.7 contains an authentication bypass vulnerability in the monitor router endpoints that allows unauthenticated attackers to access destructive operations. Remote attackers can invoke the /monitor/actions/cleanup endpoint and manipulate monitoring state without authentication, causing service disruption.

References (3)

Core 3
Core References
Third Party Advisory third-party-advisory
VulnCheck Advisory: Crawl4AI - Unauthenticated Access to Monitor Endpoints via Docker API Server
https://www.vulncheck.com/advisories/crawl4ai-unauthenticated-access-to-monitor-endpoints-via-docker-api-server

Scores

CVSS v3 6.5
EPSS 0.0042
EPSS Percentile 34.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (3)
Crawl4AI/Crawl4AI < 0.8.7
Crawl4AI/Crawl4AI 0.8.7
kidocode/crawl4ai < 0.8.7
Published Jun 24, 2026
Tracked Since Jun 24, 2026