Web Application Firewall Vulnerability in BunkerWeb by Bunkerity
CVE-2026-54728
6.1MEDIUM
What is CVE-2026-54728?
A vulnerability in the BunkerWeb Web Application Firewall allows authenticated low-privileged users to exploit improper Host header handling. This issue stems from insufficient validation and sanitization of user-controlled input, leading to potential privilege escalation and risks to the confidentiality, integrity, and availability of the affected BunkerWeb instances. The vulnerability has been addressed in BunkerWeb version 1.6.12 and BunkerWeb PRO version 0.57. Users are strongly advised to update to the latest versions to mitigate the risk.
Affected Version(s)
bunkerweb < 1.6.12
