Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers can access administrative controllers to read user listings, create manager accounts, and register managed systems, gaining control over SSH access to the managed fleet.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-288"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75627.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "5.1.0"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75627.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "302047522726612019582120512413827961495",
"length": 625
},
"id": "CVE-2026-75627-01858233",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
"target": {
"file": "src/test/java/loophole/mvc/base/BaseKontrollerExecuteTest.java",
"function": "stripsQuotesFromBracketedParameterKey"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "199258960994840768801617323500969597505",
"length": 308
},
"id": "CVE-2026-75627-073a4332",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
"target": {
"file": "src/test/java/loophole/mvc/base/BaseKontrollerExecuteTest.java",
"function": "doesNotInvokeControllerMethodWhenHttpMethodDoesNotMatch"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"193824396252684728063001484174684226534",
"197080244004145042948327157892127429773",
"166776754402698981237552379874307282761",
"170013315515999957247356211766833516164",
"153598416542175048614078520788800027471",
"35820544237400732462057694992544528135",
"127077442639592750654187331744194691539",
"124031150929166538110226749394651773023",
"284903775854258554480629260751814976223",
"309273998830710011178705223494755779564",
"84631180735340755823180062132861391637",
"339631979007708136365531932306031144234",
"281495365852892570635716828475872123957",
"14986263903821859995467086800199636871",
"49471467178511156521801688028948033764",
"224089778259474872981547778289879113250"
],
"threshold": 0.9
},
"id": "CVE-2026-75627-138207b0",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
"target": {
"file": "src/test/java/loophole/mvc/base/DispatcherServletTest.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "214249371367930942594964606302797771595",
"length": 287
},
"id": "CVE-2026-75627-159a00e3",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
"target": {
"file": "src/test/java/loophole/mvc/base/DispatcherServletTest.java",
"function": "unmatchedForwardOnAnAlreadyCommittedResponseDoesNotAttemptSendError"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "316893996809433818343677667514016869549",
"length": 759
},
"id": "CVE-2026-75627-1eed02b3",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
"target": {
"file": "src/main/java/io/bastillion/manage/socket/SecureShellWS.java",
"function": "onOpen"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "106357714796329960548325237575942975660",
"length": 351
},
"id": "CVE-2026-75627-20cac6fd",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
"target": {
"file": "src/test/java/loophole/mvc/base/DispatcherServletTest.java",
"function": "forwardsToViewReturnedByController"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "127306233333222486834294375910028442843",
"length": 619
},
"id": "CVE-2026-75627-23fa6d49",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
"target": {
"file": "src/test/java/loophole/mvc/base/BaseKontrollerExecuteTest.java",
"function": "handlesBracketedParameterKeyMissingClosingBracket"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "147238379328134725715962947012201896780",
"length": 404
},
"id": "CVE-2026-75627-24b46fbd",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
"target": {
"file": "src/test/java/loophole/mvc/base/BaseKontrollerExecuteTest.java",
"function": "invokesControllerMethodMatchingPathAndHttpMethod"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "177035832814905769811440062199463092983",
"length": 686
},
"id": "CVE-2026-75627-2cc79f16",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
"target": {
"file": "src/test/java/loophole/mvc/base/BaseKontrollerExecuteTest.java",
"function": "skipsExecuteMethodAndReturnsValidationInputWhenValidateAddsFieldError"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"109458046077551543042191136146781242403",
"201756178357233716193341110171152063533",
"255414789537943351686107116236264447545",
"329251305714051304880803414368441806762",
"173775682591512703659617132600808246077",
"124462769918480878181391870694976718142",
"120869908351195111535749713335822974328",
"171066037737503494257648033984016339645",
"276557223366971315029625182492060756036",
"218317338785410685162438116231160439020",
"61854763406717276289353362384968544908",
"306322855909946489420739023678367136287",
"121115579156419155521494975072162644628",
"57211717095011236826982424535325491591",
"248605509258165324149745461895145460968",
"223608342197697156610291408217378992209",
"335284243546497760686616977920301585414",
"75531605491199870116545700751011721471",
"25681108396694273617860619244050133219",
"177980242591394377863159481782574722962",
"183354044868842639282564317384669573862",
"47478914520778998592266946933012562892",
"281487404892005538961911137656080022732",
"25126981143028120667437849936398443190",
"85485291442291985816005005335934691605",
"338487092976674953434466819600717604981",
"163603051227968934520136302513477549396",
"58959799412372027647168117379873398819",
"137762091617009465134933466701099274302",
"98570063401079778796971222065779481260",
"127226036359298155912779223592371813994",
"253818299148757184144907339274343034027"
],
"threshold": 0.9
},
"id": "CVE-2026-75627-4dea18f6",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
"target": {
"file": "src/test/java/loophole/mvc/base/BaseKontrollerExecuteTest.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"311219038643382896495680625200976993598",
"47698881658597565719228310305628932306",
"252014944294223245939017951913993997989",
"126635173006550800463132290207961008754",
"269164831292645585197171117041528687902",
"197772108202444248545787542955706231696",
"79473884910578009305889084996122308610",
"316869590091515561158023153230911000418",
"108617384494726934982889180642701277411",
"304573078646780258203538040715213388937",
"308743202808405983992992723397615561148",
"73683559406046979779831784757339459578",
"254677163302501661873200468726021430580",
"241685096483929967820862104994209174621",
"189406428705736960801901789778537147122",
"245248132350394207111077370891926009238",
"286958945159549554525702423258520320946",
"199710990182788164166446614217627291156",
"35667145348277290151539964999866141297",
"32183657053522484135273057903277526996",
"13400829124019663126883112940927779550",
"23597743900231912314982926767401547744",
"178710742005336651830020800934757495128",
"194194620634857213645548129561820264435"
],
"threshold": 0.9
},
"id": "CVE-2026-75627-56977a97",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
"target": {
"file": "src/main/java/io/bastillion/manage/control/LoginKtrl.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "146737148374655700146655064475959288831",
"length": 667
},
"id": "CVE-2026-75627-5a53de75",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
"target": {
"file": "src/test/java/loophole/mvc/base/BaseKontrollerExecuteTest.java",
"function": "populatesMapModelFieldFromBracketedParameterName"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"142703019316893694888284346272216022115",
"152476493396534406812848274480157900618",
"144984276348153896436124458534171938631",
"151968349311916619167976416673914245712"
],
"threshold": 0.9
},
"id": "CVE-2026-75627-a0859b5f",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
"target": {
"file": "src/main/java/io/bastillion/common/filter/AuthFilter.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "325798657237994420723036345712116991670",
"length": 653
},
"id": "CVE-2026-75627-a4194c5a",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
"target": {
"file": "src/test/java/loophole/mvc/base/BaseKontrollerExecuteTest.java",
"function": "populatesModelAnnotatedFieldsFromRequestParametersAndBack"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "205914588541578032264324270991299748958",
"length": 517
},
"id": "CVE-2026-75627-a540f273",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
"target": {
"file": "src/test/java/loophole/mvc/base/BaseKontrollerExecuteTest.java",
"function": "handlesAdversarialBracketedParameterNameWithoutQuadraticSlowdown"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "112650395610541313216915703364468428248",
"length": 2166
},
"id": "CVE-2026-75627-b334f1ef",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
"target": {
"file": "src/main/java/io/bastillion/manage/control/LoginKtrl.java",
"function": "loginSubmit"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"39108634396453363512137112979241752071",
"128987413345316311544954419155197865394",
"64111268182138392738556808458078611991",
"120095997768640523963887229506429590879",
"244096217942773172606319876428155022838",
"44676050019751309409495348030752280507",
"339611586861617160344730906988165499145",
"147390796916144036899071348745071319026",
"334047802613962569673657691212767711818",
"134474189669874576389022316860597117587",
"218688610510947085752981251620125603811",
"181764694941146801550711911365220564514",
"119817979076503306512270852971974700335",
"128173374995324360841757187318854555942",
"203859751780617765799070683020660972116",
"85519590371758540358615618576583530167"
],
"threshold": 0.9
},
"id": "CVE-2026-75627-b54acc37",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
"target": {
"file": "src/main/java/io/bastillion/manage/socket/SecureShellWS.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "88213556873673919973080127743824251516",
"length": 492
},
"id": "CVE-2026-75627-c4b810fc",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
"target": {
"file": "src/test/java/loophole/mvc/base/DispatcherServletTest.java",
"function": "redirectsAndAppendsCsrfTokenFromSession"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"189272480504082291782609967122300056959",
"4124558495824483303001020805867138664",
"80724125710690664276350461460771780234",
"37560194970812787784940391341690862658"
],
"threshold": 0.9
},
"id": "CVE-2026-75627-ea157047",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
"target": {
"file": "src/main/java/loophole/mvc/base/BaseKontroller.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "243236184376157731735476385311330097618",
"length": 295
},
"id": "CVE-2026-75627-f13096b2",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
"target": {
"file": "src/test/java/loophole/mvc/base/DispatcherServletTest.java",
"function": "unmatchedUriWithNothingWrittenYetSends404"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"110396338135353324027329242859418443300",
"212669928949245496127551652673956782213",
"322345668627863902057464920279574717913",
"268615777942151801307763125172946932533",
"170088811096970146724631828807205786969",
"188215320482007166676983989510814338081",
"125004997967838587072287312125187596621",
"91639420279880476202095184273918862812",
"114889614032053956236398171709186583293",
"324785196232598550360870832518671267550",
"151085070162374444832606377514819015107",
"157764284741877913447068427559108794246",
"168461245703009204965585952540742270814",
"302202436563573877330020349736517619940",
"25995584182825028914933506050716562451",
"85364862415870027695857254579943850967"
],
"threshold": 0.9
},
"id": "CVE-2026-75627-f9a35209",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
"target": {
"file": "src/test/java/io/bastillion/common/filter/AuthFilterTest.java"
}
}
]
"2026-08-20T09:52:36Z"