SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-75627

CRITICAL · CVSS 9.8 EPSS 0.44% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Bastillion is vulnerable due to improper validation of request URI paths, enabling unauthenticated attackers to bypass authentication filters and access administrative controllers. This flaw allows attackers to read user listings, create manager accounts, and register managed systems, potentially compromising SSH access to the entire managed fleet. Organizations using Bastillion should prioritize patching this vulnerability to prevent unauthorized access and control over their systems.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-75627
Severity
CRITICAL
CVSS
9.8
EPSS
0.44%

Original NVD Description

Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers can access administrative controllers to read user listings, create manager accounts, and register managed systems, gaining control over SSH access to the managed fleet.