Impact
From version 1.6.2 through 1.6.11, the web UI of BunkerWeb allows read‑only users to exploit a missing authorization check on the /cache/ routes. The POST /cache/delete endpoint is protected only by a login requirement, enabling a low‑privilege user to permanently delete job cache files that contain blacklist, greylist, DNSBL, CrowdSec, GeoIP, ModSecurity CRS, Let’s Encrypt, ACME, and custom configuration data. This deletion capability removes essential runtime configuration and can disrupt the operation of the WAF.
Affected Systems
The affected product is Bunkerity BunkerWeb. Versions affected are 1.6.2 through 1.6.11 inclusive. All deployments relying on the default BiscuitMiddleware authorization list that includes the /cache/ prefix are susceptible until an upgrade or configuration change is performed.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. The EPSS score of less than 1% suggests a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the web UI, requiring authentication but limited to users with read‑only access. Although the impact is limited to deletion of cache files rather than code execution, the loss of configuration data can lead to service disruption or forced re‑configuration, making the vulnerability relevant for administrators who rely on automated cache management.
OpenCVE Enrichment