Authorization Bypass in BunkerWeb WAF Affects User Data
CVE-2026-61718
5.4MEDIUM
What is CVE-2026-61718?
BunkerWeb, an open-source web application firewall, had an issue present in versions 1.6.2 to 1.6.12 where the BiscuitMiddleware authorization bypass list improperly included routes meant to be protected. This flaw allowed low-privilege accounts to access and delete sensitive files from the job cache, compromising data security. The vulnerability has been addressed in version 1.6.12.
Affected Version(s)
bunkerweb >= 1.6.2, < 1.6.12
