CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-25555

Critical · CVSS 9.8

OpenBullet2 — Authentication Bypass via Empty API Key Header

CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-305

Description

OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middleware that allows unauthenticated attackers to gain admin access by supplying an empty X-Api-Key header value. Attackers can exploit the middleware's comparison of the supplied header against an empty AdminApiKey default string to access the admin console and all API endpoints without valid credentials.

Search profile — drives PoC discovery

Symbols X-Api-KeyAdminApiKeyApiKeyMiddlewareX-Api-Key headerempty headeradmin consoleAPI key authentication middleware
Keywords CVE-2026-25555OpenBullet2authentication bypassX-Api-KeyAdminApiKeyempty headeradmin bypassAPI key middlewareCWE-305auth bypass OpenBullet2
Versions: <= 0.3.2

Ranked PoCs (1) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-14T18:30:20.000Z