S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jun 17, 2026

CVE-2026-25555 Scanner

CVE-2026-25555 Scanner - Unauthorized Admin Access vulnerability in OpenBullet2

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.1k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-25555
9.3
CVSScritical
Exploitable remotely over the internet · no authentication required.

OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middleware that allows unauthenticated attackers to gain admin access by supplying an empty X-Api-Key header value. Attackers can exploit the middleware's comparison of the supplied header against an empty AdminApiKey default string to access the admin console and all API endpoints without valid credentials.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
openbullet2by openbullet
0
Updated Aug 22, 2026View on NVD →
Detail

OpenBullet2 is a software commonly used for testing and automation with headless browsing capabilities, often favored in penetration testing environments. Developed and maintained by OpenBullet, it allows for a variety of tasks including web scraping, penetration testing, and data parsing. Primarily utilized by cybersecurity enthusiasts and professionals, it supports fast bot-based tasks to automate web interactions. Its popular use stems from the flexibility in configuring complex tasks with ease and its open-source nature enables community-driven improvements and updates. OpenBullet2 is deployed over various network environments and often integrates with other tools in the security and research toolkit. The flexibility and robust features offered by OpenBullet2 make it a preferred choice for technical assessments and automations.

The detected vulnerability within OpenBullet2 pertains to an unauthorized admin access flaw. This vulnerability emerges due to improper API key authentication middleware handling the empty X-Api-Key header. Consequently, it allows unauthenticated attackers to exploit the system by circumventing authentication measures and gaining full admin rights. Such a critical flaw poses risks as it exposes sensitive administrative interfaces to potentially malicious actors without the need for initial authentication. OpenBullet2 versions at or below 0.3.2 are affected and require immediate attention to mitigate potential security breaches. Prompt resolution of this vulnerability is crucial to prevent unauthorized disruptions or manipulations within OpenBullet instances.

The vulnerability details entail an exploitation stemming from accepting requests with empty X-Api-Key headers. Attackers can bypass intended authentication checks, which should ordinarily restrict access to only those providing a valid API key. The exploitation involves crafting specific raw HTTP requests to the application server while ensuring the key header remains empty, yet fulfilling all other necessary conditions to elicit a 200 status from the server. This oversight in handling the API key validation process leaves backend systems exposed to unauthorized control. Endpoint and associated server api's requests are vulnerable points due to this bypass.

Exploiting this vulnerability can lead to unauthorized access by attackers who could potentially gain control over the entire software system. It creates a serious risk of system compromise, where attackers could manipulate application settings, extract sensitive information, or deploy further malicious activities leveraging admin rights. Given the high CVSS score, potential impacts include data theft, unauthorized system changes, downtime, or total compromise of productivity applications dependent on OpenBullet infrastructure.

REFERENCES

Solution Advice
  • Upgrade OpenBullet2 to a version later than 0.3.2 to fix the authentication bypass vulnerability.
  • Implement strict API key verifications to ensure empty headers are not accepted.
  • Conduct regular audits and penetration tests to identify potential security flaws in authentication protocols.
  • Segment networks to minimize the impact potential unauthorized access could have on other system components.
  • Regularly update software components to protect against known vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.