This is an insecure default initialization flaw in Caddy Proxy Manager's authentication flow. Before the fix, email and password self-registration was enabled by default at /api/auth/sign-up/email, allowing an unauthenticated remote actor to submit registration and receive an active account with the user role. That role cannot view or modify proxy data, so the available evidence does not establish a direct path to administrator privileges or proxy data.
The fix adds config.auth.allowSelfRegistration, derived from AUTH_ALLOW_SELF_REGISTRATION === "true", and passes its inverse to disableSignUp in src/lib/auth-server.ts. When the control is disabled, the developer test confirms that the endpoint returns EMAIL_PASSWORD_SIGN_UP_DISABLED; when intentionally enabled, the test confirms that registration creates a user account. The underlying authentication-library behavior and any additional limits of the user role are not described in greater detail by the available sources.