OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-90481

CRITICAL · CVSS 9.2 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

An authentication bypass vulnerability exists in PortSwigger Burp Suite DAST prior to version 2026.8, allowing unauthorized access through alternate channels. This critical flaw, rated 9.2 on the CVSS scale, poses a significant risk to organizations relying on this tool for security testing. Users of affected versions should prioritize immediate updates to mitigate potential exploitation.

CVE
CVE-2026-90481
Severity
CRITICAL
CVSS
9.2
EPSS
0.33%

Original NVD Description

In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an authentication bypass can occur via an alternate path or channel.