The BunkerWeb web UI BiscuitMiddleware authorization bypass vulnerability allowed low-privilege reader accounts to permanently delete job cache files containing sensitive configuration data. This issue was fixed in version 1.6.12. The vulnerability affects BunkerWeb versions 1.6.2 through 1.6.11. The vulnerability was reported by a security researcher and fixed by the vendor. The CVE record was published [truncated]
CVE-2026-54728 is a vulnerability in BunkerWeb, a next-generation Web Application Firewall (WAF). Authenticated users could escalate privileges via improper handling of the Host header in the BunkerWeb UI and API. This issue affects confidentiality, integrity, and availability. The vulnerability has a CVSS score of 6.1 and is classified as MEDIUM severity. Administrators and users of affected versions sho [truncated]