Web Application Firewall Vulnerability in BunkerWeb by Bunkerity
CVE-2026-54728

6.1MEDIUM

Key Information:

Vendor

Bunkerity

Status
Vendor
CVE Published:
16 July 2026

What is CVE-2026-54728?

A vulnerability in the BunkerWeb Web Application Firewall allows authenticated low-privileged users to exploit improper Host header handling. This issue stems from insufficient validation and sanitization of user-controlled input, leading to potential privilege escalation and risks to the confidentiality, integrity, and availability of the affected BunkerWeb instances. The vulnerability has been addressed in BunkerWeb version 1.6.12 and BunkerWeb PRO version 0.57. Users are strongly advised to update to the latest versions to mitigate the risk.

Affected Version(s)

bunkerweb < 1.6.12

References

CVSS V4

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.