CVE-2026-25559: high-severity vulnerability in openbullet2
OpenBullet2 0.3.2 Path Traversal via Wordlist Endpoint
Published · Updated
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 8.7epss 0.9%
exploitation probability
0.9%top 42% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
OpenBullet2 through version 0.3.2 contains a path traversal vulnerability in the wordlist endpoint that allows authenticated attackers to perform arbitrary file read, write, and delete operations by supplying unsanitized absolute paths to the upload handler and wordlist functions. Attackers can chain the file write and delete primitives to achieve remote code execution by manipulating critical system files such as /etc/passwd, with full system impact since the application runs as root by default.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
openbullet · openbullet2public PoCs found — 1
cve_referencehackernoon.com/one-empty-header-to-admin-how-an-auth-bypass-breaks-openbullet2unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — openbullet2
In the same product, most dangerous first.
CVE-2026-25555CRITICALOpenBullet2 0.3.2 Authentication Bypass via X-Api-Key HeaderEPSS 2.7%CVE-2026-25855HIGHOpenBullet2 0.3.2 Authenticated RCE via FileProxySource Script UploadEPSS 1.1%CVE-2026-25856HIGHOpenBullet2 0.3.2 Authenticated RCE via Job Configuration InterfaceEPSS 0.9%CVE-2026-39908HIGHOpenBullet2 0.3.2 NTLMv2 Hash Disclosure via UNC Path Proxy SourceEPSS 0.5%