PT-2026-60565 · Bunkerweb · Bunkerweb
CVE-2026-61718
·
Published
2026-07-16
·
Updated
2026-07-16
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
bunkerweb versions 1.6.2 through 1.6.11
Description
The web UI BiscuitMiddleware authorization bypass list incorrectly included the
/cache/ URL prefix. This allowed users with low-privilege read-only reader accounts to access routes in src/ui/app/routes/cache.py that were only protected by the @login required decorator. Specifically, an attacker could use the POST /cache/delete endpoint to permanently delete job cache files containing critical data such as blacklist, greylist, DNSBL, CrowdSec, GeoIP, ModSecurity CRS, Let's Encrypt, ACME, and custom configuration data.Recommendations
Update bunkerweb to version 1.6.12.
Exploit
Fix
Missing Authorization
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bunkerweb