Back to CVE List

CVE-2026-25555

CRITICAL SEVERITY

CVSS Score & Metrics

Base Score
9.8 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Description

OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middleware that allows unauthenticated attackers to gain admin access by supplying an empty X-Api-Key header value. Attackers can exploit the middleware's comparison of the supplied header against an empty AdminApiKey default string to access the admin console and all API endpoints without valid credentials.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-305
Source
NVD
Vendor
openbullet
Product
openbullet2

External References

Discussion (0)

Add Comment

No comments yet. Be the first!