PT-2026-47343 · Git+1 · Openbullet2

·

CVE-2026-25856

·

Published

2026-06-08

·

Updated

2026-06-08

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenBullet2 versions prior to 0.3.3
Description Authenticated users can execute arbitrary C# code on the server host by creating or modifying job configurations. This is possible because the plain C# execution mode does not implement reference filtering or API restrictions, allowing an attacker to access the file system, spawn processes, and invoke arbitrary .NET APIs with the privileges of the process user.
Recommendations Update to a version newer than 0.3.2.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-25856

Affected Products

Openbullet2