CVE-2026-25555
CRITICAL NUCLEIOpenBullet2 0.3.2 Authentication Bypass via X-Api-Key Header
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-25555. PoCs published by thecodeb0ss. A Nuclei detection template is also available.
AI-analyzed exploit summary The repository contains no actual exploit code or technical details about CVE-2026-25555. It only includes a README with an image and a Telegram link, suggesting external distribution of the PoC, which is a common social engineering tactic.
Description
OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middleware that allows unauthenticated attackers to gain admin access by supplying an empty X-Api-Key header value. Attackers can exploit the middleware's comparison of the supplied header against an empty AdminApiKey default string to access the admin console and all API endpoints without valid credentials.
Exploits (1)
The repository contains no actual exploit code or technical details about CVE-2026-25555. It only includes a README with an image and a Telegram link, suggesting external distribution of the PoC, which is a common social engineering tactic.
Nuclei Templates (1)
title="Openbullet2WebClient"
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H