Vulnerability Description
OpenBullet2 through version 0.3.2 contains an authenticated remote code execution vulnerability that allows authenticated users to execute arbitrary C# code on the server host by creating or modifying job configurations. Attackers can leverage the plain C# execution mode, which lacks reference filtering or API restrictions, to access the file system, spawn processes, and invoke arbitrary .NET APIs as the process user.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://hackernoon.com/one-empty-header-to-admin-how-an-auth-bypass-breaks-openb
- https://www.vulncheck.com/advisories/openbullet2-authenticated-rce-via-job-confi
FAQ
What is CVE-2026-25856?
CVE-2026-25856 is a vulnerability with a CVSS score of 8.8 (HIGH). OpenBullet2 through version 0.3.2 contains an authenticated remote code execution vulnerability that allows authenticated users to execute arbitrary C# code on the server host by creating or modifying...
How severe is CVE-2026-25856?
CVE-2026-25856 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-25856?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.