CVE-2026-75627: Bastillion Authentication Bypass via Path-Prefix Routing Mismatch

Published Aug 18, 2026
·
Updated

Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers can access administrative controllers to read user listings, create manager accounts, and register managed systems, gaining control over SSH access to the managed fleet.

Affected Software

1 affected component
Bastillion

Event History

Aug 18, 2026
CVE Published
via MITRE·10:46 AM
Data Sourced
via MITRE·10:46 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can realistically exploit this issue?

Any Bastillion instance whose web interface is reachable by an attacker is exposed, because exploitation is network-based and requires no authentication or user interaction. The issue can provide access to administrative controller functions.

2

What does an attacker need to exploit it?

An attacker needs only to send requests with arbitrary path segments prefixed to target URIs, exploiting the dispatcher’s path-prefix routing mismatch. No credentials or prior privileges are required.

3

What could an attacker do after bypassing authentication?

Successful exploitation can expose user listings, allow creation of manager accounts, and permit registration of managed systems. This can give the attacker control over SSH access to the managed fleet.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203