Junglewise Threat Intelligence

CVE-2026-25856: OpenBullet2 authenticated remote code execution in job configurations

CVE-2026-25856 · Severity: high · CVSS 8.8 · Published 2026-06-08

Technologies: OpenBullet2. Vendors: OpenBullet2.

Executive brief

OpenBullet2, an automation suite used for web testing and data scraping, contains a flaw that allows users with login credentials to take full control of the server. By creating or modifying specific job configurations, an attacker can run malicious commands directly on the host system. This could lead to the theft of sensitive data, complete system takeover, or the use of the server for further attacks.

Technical details

An authenticated remote code execution (RCE) vulnerability exists in OpenBullet2 through version 0.3.2 due to improper control of generation of code (CWE-94). The application's job configuration interface allows users to utilize a 'plain C#' execution mode that lacks adequate reference filtering or API restrictions. An attacker with low-privileged authenticated access can create or modify a job to execute arbitrary C# code, enabling them to access the underlying file system, spawn new processes, and invoke .NET APIs with the privileges of the service user. The vulnerability is reachable over the network and does not require user interaction beyond the attacker's own actions.

Affected products

  • OpenBullet2 OpenBullet2 through 0.3.2

Timeline

  • 2026-06-06: disclosed: Initial researcher disclosure by Maksim Rogov
  • 2026-06-08: advisory: NVD and VulnCheck published advisory details

References

Related threats