CVE-2026-90481: Critical severity PortSwigger Burp Suite DAST vulnerability
In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an authentication bypass can occur via an alternate path or channel.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PortSwigger Burp Suite DASTto a version that resolves this vulnerability.Fixed in 2026.8
Event History
Frequently Asked Questions
Which deployments are affected?
PortSwigger Burp Suite DAST installations running versions before 2026.8 are affected. The provided information does not state any configuration prerequisites.
What is required to exploit this issue?
The issue is described as an authentication bypass through an alternate path or channel. The provided information does not specify the attacker’s required access level, network position, or the affected interface.
What should teams do to remediate it?
Upgrade PortSwigger Burp Suite DAST to version 2026.8 or later. No temporary mitigation or detection method is provided.