PT-2026-60565 · Bunkerweb · Bunkerweb

CVE-2026-61718

·

Published

2026-07-16

·

Updated

2026-07-16

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions bunkerweb versions 1.6.2 through 1.6.11
Description The web UI BiscuitMiddleware authorization bypass list incorrectly included the /cache/ URL prefix. This allowed users with low-privilege read-only reader accounts to access routes in src/ui/app/routes/cache.py that were only protected by the @login required decorator. Specifically, an attacker could use the POST /cache/delete endpoint to permanently delete job cache files containing critical data such as blacklist, greylist, DNSBL, CrowdSec, GeoIP, ModSecurity CRS, Let's Encrypt, ACME, and custom configuration data.
Recommendations Update bunkerweb to version 1.6.12.

Exploit

Fix

Missing Authorization

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61718
GHSA-Q7RM-935C-V39G

Affected Products

Bunkerweb