LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-25555

Published
CVSS9.8
Severitycritical
WeaknessCWE-305
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middleware that allows unauthenticated attackers to gain admin access by supplying an empty X-Api-Key header value. Attackers can exploit the middleware's comparison of the supplied header against an empty AdminApiKey default string to access the admin console and all API endpoints without valid credentials.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-25555

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-25555.