Junglewise Threat Intelligence

CVE-2026-61718: Bunkerity BunkerWeb authorization bypass in cache management routes

CVE-2026-61718 · Severity: medium · CVSS 5.4 · Published 2026-07-16

Technologies: Bunkerity BunkerWeb. Vendors: Bunkerity.

Executive brief

BunkerWeb, an open-source web application firewall (WAF), contains a security flaw in its management interface. The vulnerability allows users with restricted, read-only access to bypass security controls and delete critical system cache files. An attacker with low-level credentials could use this to remove security rules, IP blacklists, and configuration data, potentially weakening the firewall's protection and disrupting service availability.

Technical details

An authorization bypass exists in the BunkerWeb web UI's BiscuitMiddleware. The middleware's bypass list incorrectly included the '/cache/' URL prefix, causing requests to routes in 'src/ui/app/routes/cache.py' to skip permission checks. While these routes were protected by a '@login_required' decorator, they lacked specific role-based access control (RBAC) checks. Consequently, an authenticated user with only 'reader' (read-only) privileges could successfully execute a 'POST /cache/delete' request. This allows the permanent deletion of job cache files containing sensitive data such as DNSBLs, GeoIP databases, ModSecurity CRS rules, and ACME/Let's Encrypt material. The issue is resolved in version 1.6.12 by removing the prefix from the bypass list and enforcing proper authorization.

Affected products

  • Bunkerity BunkerWeb 1.6.2 - 1.6.11

Timeline

  • 2026-06-12: patched: Fix committed to repository
  • 2026-07-02: advisory: Version 1.6.12 released
  • 2026-07-08: disclosed: GitHub Security Advisory published
  • 2026-07-16: advisory: NVD record published

References

Related threats