Back to overview

CVE-2026-25555

CRITICAL Exploitation: PoC
9.8
CVSS 3.1
Description
OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middleware that allows unauthenticated attackers to gain admin access by supplying an empty X-Api-Key header value. Attackers can exploit the middleware's comparison of the supplied header against an empty AdminApiKey default string to access the admin console and all API endpoints without valid credentials.

Metadata

CVE ID
CVE-2026-25555
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-02-02 20:12 UTC
Published
2026-06-08 16:53 UTC
Last updated
2026-07-14 15:53 UTC
Primary CWE
CWE-305
Authentication Bypass by Primary Weakness
Vendor / Product
openbullet / openbullet2
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
openbullet openbullet2 0 ≤ 0.3.2
Weakness (CWE)
CWESourceDescription
CWE-305 cna Authentication Bypass by Primary Weakness
CVSS scores (2)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.3 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Back to overview