Description
bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). Prior to BunkerWeb 1.6.12 and BunkerWeb PRO 0.57, authenticated Host header handling in the BunkerWeb UI and API improperly validated and neutralized user-controlled input in a configuration-dependent path, allowing a low-privileged authenticated user to escalate privileges and affect confidentiality, integrity, and availability of the BunkerWeb instance. This issue is fixed in BunkerWeb version 1.6.12 and BunkerWeb PRO version 0.57.
Published: 2026-07-16
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an improper input validation and neutralization of special elements that occurs when the BunkerWeb UI or API accepts a Host header from an authenticated user. The unvalidated input can be inserted into a configuration‑dependent path, allowing a low‑privileged authenticated user to inject data that effectively changes configuration files or directives. This leads to a privilege escalation where the attacker gains the level of a fully‑authorized administrator, and subsequently can compromise the confidentiality, integrity, or availability of the entire BunkerWeb instance.

Affected Systems

The open‑source BunkerWeb distribution and the BunkerWeb PRO edition are affected. All releases before open‑source version 1.6.12 and before PRO version 0.57 contain the flawed Host header handling logic in the admin UI and API.

Risk and Exploitability

The CVSS score of 6.1 reflects a moderate risk; the EPSS score of less than 1% indicates a very low likelihood that the vulnerability is currently being abused. BunkerWeb is not listed in the CISA KEV catalog. The most likely attack vector is a local authenticated user with limited privileges able to interact with the UI or API; by sending a crafted Host header the attacker can modify configuration and elevate privileges. A successful exploit would give the attacker full control over the web application firewall.

Generated by OpenCVE AI on July 31, 2026 at 01:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade BunkerWeb to the latest released version – BunkerWeb 1.6.12 for the community edition or BunkerWeb PRO 0.57 for the professional edition – which include the Host header handling fix.
  • If an upgrade cannot be performed immediately, limit the Host header manipulation endpoint to a very small set of privileged users or disable it entirely so that low‑privileged accounts cannot alter configuration.
  • Enforce least privilege by ensuring that only users who require administrative configuration changes have rights to modify the Host header; remove or restrict permissions for all other accounts.

Generated by OpenCVE AI on July 31, 2026 at 01:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Bunkerity
Bunkerity bunker Web
Vendors & Products Bunkerity
Bunkerity bunker Web

Fri, 17 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Description bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). Prior to BunkerWeb 1.6.12 and BunkerWeb PRO 0.57, authenticated Host header handling in the BunkerWeb UI and API improperly validated and neutralized user-controlled input in a configuration-dependent path, allowing a low-privileged authenticated user to escalate privileges and affect confidentiality, integrity, and availability of the BunkerWeb instance. This issue is fixed in BunkerWeb version 1.6.12 and BunkerWeb PRO version 0.57.
Title bunkerweb: Improper Input Validation and Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in BunkerWeb
Weaknesses CWE-20
CWE-74
References
Metrics cvssV4_0

{'score': 6.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Bunkerity Bunker Web
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-17T13:47:18.414Z

Reserved: 2026-06-15T23:07:33.232Z

Link: CVE-2026-54728

cve-icon Vulnrichment

Updated: 2026-07-17T13:47:13.499Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T01:30:05Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')