Security Advisory

CVE-2026-54728

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-16 19:18:17
Last updated 2026-07-17 13:47:18
Assigner GitHub_M
CVSS score 6.1
State PUBLISHED

Description

bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). Prior to BunkerWeb 1.6.12 and BunkerWeb PRO 0.57, authenticated Host header handling in the BunkerWeb UI and API improperly validated and neutralized user-controlled input in a configuration-dependent path, allowing a low-privileged authenticated user to escalate privileges and affect confidentiality, integrity, and availability of the BunkerWeb instance. This issue is fixed in BunkerWeb version 1.6.12 and BunkerWeb PRO version 0.57.