Skip to content

Known CVE

OpenBullet2 <= 0.3.2 - Authentication Bypass

OpenBullet2 <= 0.3.2 contains an authentication bypass caused by improper API key authentication middleware handling empty X-Api-Key header, letting unauthenticated attackers gain admin access, exploit requires sending empty X-Api-Key header.

CVE-2026-25555

Critical2026CVSS 9.8CWE-287

cve2026 · openbullet2 · auth-bypass · unauth

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website