PT-2026-60563 · Unknown+1 · Bunkerweb Pro+1

CVE-2026-54728

·

Published

2026-07-16

·

Updated

2026-07-16

CVSS v4.0

6.1

Medium

VectorAV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions BunkerWeb versions prior to 1.6.12 BunkerWeb PRO versions prior to 0.57
Description Improper validation and neutralization of user-controlled input occurs during authenticated Host header handling within the UI and API. This flaw allows a low-privileged authenticated user to escalate privileges, potentially compromising the confidentiality, integrity, and availability of the instance.
Recommendations Update BunkerWeb to version 1.6.12. Update BunkerWeb PRO to version 0.57.

Exploit

Fix

Special Elements Injection

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54728
GHSA-254J-92CV-M443

Affected Products

Bunkerweb
Bunkerweb Pro