CVE-2026-39908 Details
Description
OpenBullet2 through version 0.3.2 on Windows contains a credential disclosure vulnerability that allows remote attackers to capture the NTLMv2 hash of the process user by configuring a job proxy source with a UNC path pointing to an attacker-controlled server. When the job starts, the application attempts to load proxies from the UNC path, triggering an SMB authentication attempt that discloses the NTLMv2 hash, which can then be relayed or cracked offline.
A credential disclosure vulnerability exists in OpenBullet2 versions through 0.3.2 on Windows. This vulnerability allows remote attackers to capture the NTLMv2 hash of the process user. Exploitation involves configuring a job proxy source with a UNC path pointing to an attacker-controlled server. When the job is executed, the application attempts to load proxies from the UNC path, inadvertently triggering an SMB authentication attempt that discloses the NTLMv2 hash. This hash can then be relayed or cracked offline.
As a temporary measure, set a random API key in the OpenBullet2 settings to prevent unauthorized access. A permanent fix would require input sanitization to prevent the use of UNC paths that could lead to NTLMv2 hash disclosure.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 8, 2026CISA-ADP
Assessed Jun 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://hackernoon.com/one-empty-header-to-admin-how-an-auth-bypass-breaks-openbullet2 | [email protected] | BundleExploitRemedyTechnical Analysis |
| https://www.vulncheck.com/advisories/openbullet2-ntlmv2-hash-disclosure-via-unc-path-proxy-source | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-522 | Insufficiently Protected Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| OpenBullet2 | <= 0.3.2 (semver) |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 8, 2026 | New CVE Received | [email protected] |
Volerion