Junglewise Threat Intelligence

CVE-2026-90481: PortSwigger Burp Suite DAST authentication bypass

CVE-2026-90481 · Severity: info · Published 2026-09-24

Executive brief

Burp Suite DAST is an enterprise web vulnerability scanner used by security teams to test applications for flaws. A critical authentication bypass vulnerability could allow an attacker to access the system without proper credentials, potentially compromising scan results, credentials stored in the platform, and sensitive testing data. PortSwigger addressed this issue in version 2026.8 and recommends immediate upgrading.

Technical details

An authentication bypass exists in Burp Suite DAST before 2026.8 via an alternate path or channel. The vulnerability allows unauthenticated access to the application, though full technical details are limited in available disclosures. The fix is available in version 2026.8 and later.

Affected products

  • PortSwigger Burp Suite DAST before 2026.8

Timeline

  • 2026-09-24: disclosed
  • 2026-08-05: patched: Fixed in Burp Suite DAST 2026.8

References