MEDIUM

CVE-2026-56262

Kidocode Crawl4ai 2026-06-24 CVSS v3.1
CVSS
6.5

Description

Crawl4AI before 0.8.7 contains an authentication bypass vulnerability in the monitor router endpoints that allows unauthenticated attackers to access destructive operations. Remote attackers can invoke the /monitor/actions/cleanup endpoint and manipulate monitoring state without authentication, causing service disruption.

Summary dbcve.org

Crawl4AI versions before 0.8.7 fail to enforce authentication on monitor router endpoints. The /monitor/actions/cleanup endpoint can be invoked by remote unauthenticated attackers, allowing manipulation of monitoring state and causing service disruption through destructive cleanup operations.

Mitigation

Upgrade to Crawl4AI version 0.8.7 or later. If immediate upgrade is not feasible, implement network-level access controls to restrict access to monitor endpoints until the patch can be applied.

Weakness (CWE)

CWE-306 Missing Authentication

EPSS Score

0.76%
Probability of exploitation in next 30 days
53.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE