Impact
The flaw is an improper input validation and neutralization of special elements that occurs when the BunkerWeb UI or API accepts a Host header from an authenticated user. The unvalidated input can be inserted into a configuration‑dependent path, allowing a low‑privileged authenticated user to inject data that effectively changes configuration files or directives. This leads to a privilege escalation where the attacker gains the level of a fully‑authorized administrator, and subsequently can compromise the confidentiality, integrity, or availability of the entire BunkerWeb instance.
Affected Systems
The open‑source BunkerWeb distribution and the BunkerWeb PRO edition are affected. All releases before open‑source version 1.6.12 and before PRO version 0.57 contain the flawed Host header handling logic in the admin UI and API.
Risk and Exploitability
The CVSS score of 6.1 reflects a moderate risk; the EPSS score of less than 1% indicates a very low likelihood that the vulnerability is currently being abused. BunkerWeb is not listed in the CISA KEV catalog. The most likely attack vector is a local authenticated user with limited privileges able to interact with the UI or API; by sending a crafted Host header the attacker can modify configuration and elevate privileges. A successful exploit would give the attacker full control over the web application firewall.
OpenCVE Enrichment