Openbullet Openbullet2 vulnerabilities
5 known vulnerabilities affecting openbullet/openbullet2.
Total CVEs
5
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-25555P1CRITICALCVSS 9.8PoC≤ 0.3.22026-06-08
CVE-2026-25555 [CRITICAL] CWE-305 CVE-2026-25555: OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key aut
OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middleware that allows unauthenticated attackers to gain admin access by supplying an empty X-Api-Key header value. Attackers can exploit the middleware's comparison of the supplied header against an empty AdminApiKey default string to a
nvd
CVE-2026-25559P2HIGHCVSS 8.8≤ 0.3.22026-06-08
CVE-2026-25559 [HIGH] CWE-22 CVE-2026-25559: OpenBullet2 through version 0.3.2 contains a path traversal vulnerability in the wordlist endpoint t
OpenBullet2 through version 0.3.2 contains a path traversal vulnerability in the wordlist endpoint that allows authenticated attackers to perform arbitrary file read, write, and delete operations by supplying unsanitized absolute paths to the upload handler and wordlist functions. Attackers can chain the file write and delete primitives to achieve remo
nvd
CVE-2026-25855P2HIGHCVSS 8.8≥ 0.2.5, ≤ 0.3.22026-06-08
CVE-2026-25855 [HIGH] CWE-78 CVE-2026-25855: OpenBullet2 through version 0.3.2 contains a remote code execution vulnerability that allows authent
OpenBullet2 through version 0.3.2 contains a remote code execution vulnerability that allows authenticated users to execute arbitrary commands by uploading script files (.bat.ps1.sh) through the FileProxySource proxy loading feature. Attackers can upload malicious script files as proxy sources, causing the server to execute the scripts and return outpu
nvd
CVE-2026-25856P2HIGHCVSS 8.8≤ 0.3.22026-06-08
CVE-2026-25856 [HIGH] CWE-94 CVE-2026-25856: OpenBullet2 through version 0.3.2 contains an authenticated remote code execution vulnerability that
OpenBullet2 through version 0.3.2 contains an authenticated remote code execution vulnerability that allows authenticated users to execute arbitrary C# code on the server host by creating or modifying job configurations. Attackers can leverage the plain C# execution mode, which lacks reference filtering or API restrictions, to access the file system, s
nvd
CVE-2026-39908P3MEDIUMCVSS 6.5≤ 0.3.22026-06-08
CVE-2026-39908 [MEDIUM] CWE-522 CVE-2026-39908: OpenBullet2 through version 0.3.2 on Windows contains a credential disclosure vulnerability that all
OpenBullet2 through version 0.3.2 on Windows contains a credential disclosure vulnerability that allows remote attackers to capture the NTLMv2 hash of the process user by configuring a job proxy source with a UNC path pointing to an attacker-controlled server. When the job starts, the application attempts to load proxies from the UNC path, triggerin
nvd