# CVE-2026-25555: OpenBullet2 - Authentication Bypass

> Live exploitation tracking for CVE-2026-25555 by the CrowdSec Live Exploit Tracker, built from real-world attack data crowdsourced from CrowdSec's global network.

Page: https://tracker.crowdsec.net/cves/CVE-2026-25555

## Key facts

- **Exploitation phase:** Limited Exploitation. The vulnerability is known but shows very limited attacker interest or exploitation activity.
- **CVSS score:** 9.3
- **Public exploit available:** Yes
- **Affected products:** OpenBullet2
- **Weaknesses:** CWE-305 (Authentication Bypass by Primary Weakness)
- **Tags:** web_application

## Description

OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middleware that allows unauthenticated attackers to gain admin access by supplying an empty X-Api-Key header value. Attackers can exploit the middleware's comparison of the supplied header against an empty AdminApiKey default string to access the admin console and all API endpoints without valid credentials.

## CrowdSec analysis

[CVE-2026-25555](https://euvd.enisa.europa.eu/vulnerability/CVE-2026-25555) is a critical authentication bypass vulnerability in OpenBullet2 through version 0.3.2, where attackers can gain admin access by sending an empty X-Api-Key header. This flaw allows unauthenticated users to exploit the API key middleware and access the admin console and all API endpoints without valid credentials, potentially leading to full system compromise.

CrowdSec has been tracking this vulnerability and its exploits since 24th of June 2026.

Insights from the CrowdSec network reveal that the attackers trying to exploit CVE-2026-25555 are composed of a fairly even mix of opportunistic and targeted actors. Some attackers employ preliminary reconnaissance, while others use indiscriminate scanning.
CrowdSec data also reveals a clear uptick in attacks involving CVE-2026-25555 over the past week. Activity is above the usual baseline, suggesting growing attention from attackers. This may reflect rising awareness, recent exploit releases, or expanded targeting efforts.

Attackers exploit this vulnerability by sending requests to API endpoints such as `/api/v1/info/server` with an empty `X-Api-Key` header, bypassing authentication and gaining unauthorized admin access.

## Timeline

- 2026-06-08: CVE Published. CVE-2026-25555 is published to NVD.
- 2026-06-24: Rule Released. CrowdSec releases a rule to detect CVE-2026-25555 exploitation attempts against the CrowdSec Network.
- 2026-06-25: CrowdSec First Seen. CrowdSec observes in-the-wild exploitation of CVE-2026-25555 for the first time.

## References

- https://hackernoon.com/one-empty-header-to-admin-how-an-auth-bypass-breaks-openbullet2
- https://www.vulncheck.com/advisories/openbullet2-authentication-bypass-via-x-api-key-header
- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-25555.yaml

## Live exploitation data

The [Live Exploit Tracker page](https://tracker.crowdsec.net/cves/CVE-2026-25555) follows observed exploitation activity for CVE-2026-25555. [Request an API key](https://tracker.crowdsec.net/request-api-key) for full access to its exploitation timeline, attacking IP addresses and blocklists.
