Impact
Bastillion fails to validate request URI paths in its controller dispatcher, allowing an unauthenticated attacker to bypass authentication by prefixing requests with arbitrary path segments. This flaw lets the attacker reach administrative controllers to read user listings, create manager accounts, and register new managed systems, effectively gaining SSH access to the entire managed fleet. The vulnerability is a severe authentication bypass with potential for full system compromise.
Affected Systems
The affected product is Bastillion by bastillion-io. No specific version information is provided in the CNA data. Users should verify whether they are running an affected instance of Bastillion and seek an update where available.
Risk and Exploitability
The CVSS score of 9.3 indicates high severity and the lack of an EPSS score suggests no published exploitation data. The flaw is not listed in the CISA KEV catalog. Attackers can exploit the vulnerability remotely by crafting a URI that includes prefixed path segments; no special conditions beyond sending a crafted HTTP request are required.
OpenCVE Enrichment