CVE-2026-54728
MEDIUMbunkerweb: Improper Input Validation and Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in BunkerWeb
Title source: cnaDescription
bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). Prior to BunkerWeb 1.6.12 and BunkerWeb PRO 0.57, authenticated Host header handling in the BunkerWeb UI and API improperly validated and neutralized user-controlled input in a configuration-dependent path, allowing a low-privileged authenticated user to escalate privileges and affect confidentiality, integrity, and availability of the BunkerWeb instance. This issue is fixed in BunkerWeb version 1.6.12 and BunkerWeb PRO version 0.57.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/bunkerity/bunkerweb/security/advisories/GHSA-254j-92cv-m443
X_Refsource_Misc x_refsource_misc
https://github.com/bunkerity/bunkerweb/commit/685ccbbe7d204132a843a7b7fd802d1bdb3f20a9
X_Refsource_Misc x_refsource_misc
https://github.com/bunkerity/bunkerweb/releases/tag/v1.6.12
Scores
CVSS v4
6.1
EPSS
0.0024
EPSS Percentile
14.8%
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-20
CWE-74
Status
published
Products (1)
bunkerity/bunkerweb
< 1.6.12
Published
Jul 16, 2026
Tracked Since
Jul 17, 2026