CrowdSecLive Exploit Tracker
Limited ExploitationCVE-2026-25555Public Exploit

OpenBullet2 - Authentication Bypass (CVE-2026-25555)

PublishedJun 8, 2026
First SeenJun 25, 2026
Last Seen
Reported
CVSS9.3
web_application

Description

OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middleware that allows unauthenticated attackers to gain admin access by supplying an empty X-Api-Key header value. Attackers can exploit the middleware's comparison of the supplied header against an empty AdminApiKey default string to access the admin console and all API endpoints without valid credentials.

psychologyCrowdSec Analysis

CVE-2026-25555 is a critical authentication bypass vulnerability in OpenBullet2 through version 0.3.2, where attackers can gain admin access by sending an empty X-Api-Key header. This flaw allows unauthenticated users to exploit the API key middleware and access the admin console and all API endpoints without valid credentials, potentially leading to full system compromise.

CrowdSec has been tracking this vulnerability and its exploits since 24th of June 2026.

Insights from the CrowdSec network reveal that the attackers trying to exploit CVE-2026-25555 are composed of a fairly even mix of opportunistic and targeted actors. Some attackers employ preliminary reconnaissance, while others use indiscriminate scanning. CrowdSec data also reveals a clear uptick in attacks involving CVE-2026-25555 over the past week. Activity is above the usual baseline, suggesting growing attention from attackers. This may reflect rising awareness, recent exploit releases, or expanded targeting efforts.

Attackers exploit this vulnerability by sending requests to API endpoints such as /api/v1/info/server with an empty X-Api-Key header, bypassing authentication and gaining unauthorized admin access.

lock

Full Intelligence Available

Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.

EventDate
CVE Published2026-06-08
Rule Released2026-06-24
CrowdSec First Seen2026-06-25

Remediation & Protection

lock to download blocklists, subscribe to firewalls, and access IP intelligence.