Authentication Bypass in PortSwigger Burp Suite DAST
CVE-2026-90481

9.2CRITICAL

Key Information:

Vendor
CVE Published:
24 September 2026

What is CVE-2026-90481?

A vulnerability in PortSwigger Burp Suite DAST allows attackers to perform an authentication bypass through an alternative path or channel before version 2026.8. This flaw enables unauthorized access, leaving systems vulnerable to exploitation. Users are encouraged to update to the latest version to mitigate potential risks.

Affected Version(s)

Burp Suite DAST 2021.11 < 2026.8

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.