Executive brief
BunkerWeb is a web application firewall (WAF) designed to protect websites from cyberattacks. A security flaw in its management interface and API could allow a user with low-level access to gain full administrative control. This risk only exists if the management interface is exposed directly to the network without being protected by the WAF itself. Exploiting this could allow an attacker to modify security settings, view sensitive logs, or disable the firewall entirely.
Technical details
An authenticated privilege escalation vulnerability exists in the BunkerWeb UI and API due to improper validation of the Host header. When the UI or API is exposed directly (not behind a reverse proxy performing vhost validation), a low-privileged user can inject a crafted Host header to influence the generation of Biscuit authentication token facts. This allows the attacker to escalate their privileges to administrative levels. The root cause is a failure to properly neutralize user-controlled input in a configuration-dependent path used for token generation. The issue is fixed in BunkerWeb 1.6.12 and BunkerWeb PRO 0.57 by binding the Host header, client IP, and username as typed terms in the Biscuit tokens.
Affected products
- Bunkerity BunkerWeb < 1.6.12
- Bunkerity BunkerWeb PRO < 0.57
Timeline
- 2026-06-12: patched: Fix committed to repository
- 2026-07-02: advisory: Release v1.6.12 published
- 2026-07-08: advisory: GitHub Security Advisory published
- 2026-07-16: disclosed: CVE published to NVD