CVE-2026-54728EPSS p29.8%
CVE-2026-54728CVE-2026-54728
Description
bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). Prior to BunkerWeb 1.6.12 and BunkerWeb PRO 0.57, authenticated Host header handling in the BunkerWeb UI and API improperly validated and neutralized user-controlled input in a configuration-dependent path, allowing a low-privileged authenticated user to escalate privileges and affect confidentiality, integrity, and availability of the BunkerWeb instance. This issue is fixed in BunkerWeb version 1.6.12 and BunkerWeb PRO version 0.57.
Scoring
| EPSS | 0.38% probability of exploitation · percentile 29.8% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-17 |