CVE-2026-56115 Details
Description
Bootimus through 0.1.70 contains a broken access control vulnerability that allows authenticated low-privileged users to perform administrative actions by exploiting missing role enforcement in the JWTMiddleware function in internal/auth/auth.go, which validates JWT tokens and account status but fails to inspect the is_admin flag. Attackers can send requests to any endpoint under the /api/users path to create new administrator accounts or reset administrator passwords, thereby gaining full control of the server and the ability to modify boot menus and installation scripts served to PXE clients.
A one-byte stack out-of-bounds write vulnerability has been identified in dhcpcd versions through 10.3.2, within the dhcp6_makemessage() function in src/dhcp6.c. This vulnerability allows unauthenticated, same-link attackers to write beyond a fixed local buffer by serializing an oversized OPTION_PD_EXCLUDE option body, as specified in RFC6603. Exploitation involves sending a crafted DHCPv6 ADVERTISE message that includes an IA_PD IAPREFIX /0 and a valid OPTION_PD_EXCLUDE, using an exclude prefix length of /121 to /128. This out-of-bounds write can potentially corrupt adjacent stack memory.
Users can upgrade to dhcpcd version 10.3.3 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/garybowers/bootimus/issues/84 | [email protected] | ExploitIssue TrackingVendor Advisory |
| https://www.vulncheck.com/advisories/bootimus-broken-access-control-via-jwtmiddleware-authorization-bypass | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| bootimus bootimus | <= 0.1.70 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 29, 2026 | Reanalysis | [email protected] |
| Jun 28, 2026 | Initial Analysis | [email protected] |
| Jun 25, 2026 | CVE Modified | [email protected] |
| Jun 23, 2026 | CVE Modified | CISA-ADP |
| Jun 23, 2026 | New CVE Received | [email protected] |