CRITICAL 9.8 CVE-2026-75627 Published 18 Aug 2026

Bastillion Authentication Bypass via URI Path Validation Flaw

Worried this affects one of your servers?

Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing an authentication bypass by prefixing requests with arbitrary path segments to evade authentication filters.

Unauthenticated attackers can access administrative controllers to:

  • Read user listings
  • Create manager accounts
  • Register managed systems
  • Gain control over SSH access to the managed fleet

Reference: CVE-2026-75627 on NVD

← Back to Security News