CVE-2026-56262
Description
Crawl4AI before 0.8.7 contains an authentication bypass vulnerability in the monitor router endpoints that allows unauthenticated attackers to access destructive operations. Remote attackers can invoke the /monitor/actions/cleanup endpoint and manipulate monitoring state without authentication, causing service disruption.
Summary dbcve.org
Crawl4AI versions before 0.8.7 fail to enforce authentication on monitor router endpoints. The /monitor/actions/cleanup endpoint can be invoked by remote unauthenticated attackers, allowing manipulation of monitoring state and causing service disruption through destructive cleanup operations.
Mitigation
Upgrade to Crawl4AI version 0.8.7 or later. If immediate upgrade is not feasible, implement network-level access controls to restrict access to monitor endpoints until the patch can be applied.