Executive brief
Burp Suite DAST is an enterprise web vulnerability scanner used by security teams to test applications for flaws. A critical authentication bypass vulnerability could allow an attacker to access the system without proper credentials, potentially compromising scan results, credentials stored in the platform, and sensitive testing data. PortSwigger addressed this issue in version 2026.8 and recommends immediate upgrading.
Technical details
An authentication bypass exists in Burp Suite DAST before 2026.8 via an alternate path or channel. The vulnerability allows unauthenticated access to the application, though full technical details are limited in available disclosures. The fix is available in version 2026.8 and later.
Affected products
- PortSwigger Burp Suite DAST before 2026.8
Timeline
- 2026-09-24: disclosed
- 2026-08-05: patched: Fixed in Burp Suite DAST 2026.8