PT-2026-60563 · Unknown+1 · Bunkerweb Pro+1
CVE-2026-54728
·
Published
2026-07-16
·
Updated
2026-07-16
CVSS v4.0
6.1
Medium
| Vector | AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
BunkerWeb versions prior to 1.6.12
BunkerWeb PRO versions prior to 0.57
Description
Improper validation and neutralization of user-controlled input occurs during authenticated Host header handling within the UI and API. This flaw allows a low-privileged authenticated user to escalate privileges, potentially compromising the confidentiality, integrity, and availability of the instance.
Recommendations
Update BunkerWeb to version 1.6.12.
Update BunkerWeb PRO to version 0.57.
Exploit
Fix
Special Elements Injection
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bunkerweb
Bunkerweb Pro