216.73.217.22

CVE-2026-25559

· Published 08/06/2026 17:16 · Modified 09/06/2026 13:51

Labels: CVE-2026-25559 2026-06-08CVE-2026-25559CWE-22[email protected]

Essential information

Published
08/06/2026 17:16
Modified
09/06/2026 13:51
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

OpenBullet2 through version 0.3.2 contains a path traversal vulnerability in the wordlist endpoint that allows authenticated attackers to perform arbitrary file read, write, and delete operations by supplying unsanitized absolute paths to the upload handler and wordlist functions. Attackers can chain the file write and delete primitives to achieve remote code execution by manipulating critical system files such as /etc/passwd, with full system impact since the application runs as root by default.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
openbullet / openbullet2 cpe:2.3:a:openbullet:openbullet2:0.3.2:*:*:*:*:*:*:*

References