CVE-2026-54728 Details
Description
bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). Prior to BunkerWeb 1.6.12 and BunkerWeb PRO 0.57, authenticated Host header handling in the BunkerWeb UI and API improperly validated and neutralized user-controlled input in a configuration-dependent path, allowing a low-privileged authenticated user to escalate privileges and affect confidentiality, integrity, and availability of the BunkerWeb instance. This issue is fixed in BunkerWeb version 1.6.12 and BunkerWeb PRO version 0.57.
A vulnerability allowing authenticated privilege escalation has been identified in BunkerWeb versions prior to 1.6.12 and BunkerWeb PRO versions prior to 0.57. The issue arises from improper validation of user-controlled input in the Host header, which can be exploited by low-privileged authenticated users to inject crafted headers. This injection affects the Biscuit authentication token generation, potentially allowing the attacker to escalate privileges, including obtaining administrative rights. The vulnerability is only exploitable when the BunkerWeb UI and API are directly exposed without proper protection, such as through a reverse proxy that validates virtual hosts.
Users should upgrade to BunkerWeb version 1.6.12 or BunkerWeb PRO version 0.57. After upgrading, it is recommended to invalidate existing sessions or authentication tokens for low-privileged users if there is a suspicion that the vulnerable configuration was exposed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 16, 2026CISA-ADP
Assessed Jul 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/bunkerity/bunkerweb/commit/685ccbbe7d204132a843a7b7fd802d1bdb3f20a9 | [email protected] | Source CodeVendor |
| https://github.com/bunkerity/bunkerweb/releases/tag/v1.6.12 | [email protected] | Release NotesVendor |
| https://github.com/bunkerity/bunkerweb/security/advisories/GHSA-254j-92cv-m443 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
| CWE-74 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| bunkerity bunkerweb | < 1.6.12 (semver) |
CPE
Remediation
| |
| bunkerity bunkerweb-pro | < 0.57 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 17, 2026 | CVE Modified | CISA-ADP |
| Jul 16, 2026 | New CVE Received | [email protected] |
Volerion