CVE-2026-25555

CRITICAL NUCLEI

OpenBullet2 0.3.2 Authentication Bypass via X-Api-Key Header

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-25555. PoCs published by thecodeb0ss. A Nuclei detection template is also available.

AI-analyzed exploit summary The repository contains no actual exploit code or technical details about CVE-2026-25555. It only includes a README with an image and a Telegram link, suggesting external distribution of the PoC, which is a common social engineering tactic.

Description

OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middleware that allows unauthenticated attackers to gain admin access by supplying an empty X-Api-Key header value. Attackers can exploit the middleware's comparison of the supplied header against an empty AdminApiKey default string to access the admin console and all API endpoints without valid credentials.

Exploits (1)

github SUSPICIOUS
by thecodeb0ss · poc
https://github.com/thecodeb0ss/CVE-2026-25555

The repository contains no actual exploit code or technical details about CVE-2026-25555. It only includes a README with an image and a Telegram link, suggesting external distribution of the PoC, which is a common social engineering tactic.

Classification
Suspicious 99%
No auth needed
mistral-large-3 · analyzed Jul 06, 2026 Full analysis →

Nuclei Templates (1)

OpenBullet2 <= 0.3.2 - Authentication Bypass
CRITICALby 0x_Akoko
FOFA: title="Openbullet2WebClient"

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.0182
EPSS Percentile 76.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-305
Status published
Products (1)
openbullet/openbullet2 < 0.3.2
Published Jun 08, 2026
Tracked Since Jun 08, 2026