CVE-2026-75627

Source
https://cve.org/CVERecord?id=CVE-2026-75627
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75627.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-75627
Published
2026-08-18T10:46:54Z
Modified
2026-08-20T09:52:36Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Bastillion Authentication Bypass via Path-Prefix Routing Mismatch
Details

Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers can access administrative controllers to read user listings, create manager accounts, and register managed systems, gaining control over SSH access to the managed fleet.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-288"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75627.json"
}
References

Affected packages

Git / github.com/bastillion-io/bastillion

Affected ranges

Type
GIT
Repo
https://github.com/bastillion-io/bastillion
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "5.1.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v1.*
v1.08.20
v1.08.30
v1.08.40
v1.08.50
v1.08.51
v1.08.52
v1.08.53
v1.08.54
v2.*
v2.00.00
v2.01.00
v2.02.00
v2.02.01
v2.02.02
v2.05.00
v2.05.01
v2.05.02
v2.06.00
v2.10.00
v2.10.01
v2.10.02
v2.10.03
v2.11.00
v2.11.05
v2.12.00
v2.15.00
v2.15.10
v2.15.20
v2.15.25
v2.15.26
v2.15.27
v2.16.00
v2.17.00
v2.17.01
v2.50.00
v2.50.01
v2.50.02
v2.60.00
v2.70.01
v2.73.00
v2.73.01
v2.73.02
v2.75.00
v2.80.00
v2.82.00
v2.83.00
v2.83.01
v2.83.02
v2.84.00
v2.84.01
v2.85.01
v2.85.02
v2.85.03
v2.86.00
v2.87.00
v2.87.01
v2.88.00
v2.88.01
v2.89.00
v2.90.00
v2.90.01
v2.90.02
v2.90.03
v3.*
v3.00.00
v3.00.01
v3.00.02
v3.00.03
v3.01.00
v3.02.00
v3.05.01
v3.06.00
v3.06.01
v3.06.02
v3.06.03
v3.06.04
v3.08.00
v3.08.01
v3.09.00
v3.10.00
v3.11.01
v3.12.00
v3.12.01
v3.12.02
v3.13.00
v3.14.0
v3.15.00
v4.*
v4.0.0
v4.0.1
v5.*
v5.0.0
v5.0.1
v5.1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75627.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "302047522726612019582120512413827961495",
            "length": 625
        },
        "id": "CVE-2026-75627-01858233",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
        "target": {
            "file": "src/test/java/loophole/mvc/base/BaseKontrollerExecuteTest.java",
            "function": "stripsQuotesFromBracketedParameterKey"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "199258960994840768801617323500969597505",
            "length": 308
        },
        "id": "CVE-2026-75627-073a4332",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
        "target": {
            "file": "src/test/java/loophole/mvc/base/BaseKontrollerExecuteTest.java",
            "function": "doesNotInvokeControllerMethodWhenHttpMethodDoesNotMatch"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "193824396252684728063001484174684226534",
                "197080244004145042948327157892127429773",
                "166776754402698981237552379874307282761",
                "170013315515999957247356211766833516164",
                "153598416542175048614078520788800027471",
                "35820544237400732462057694992544528135",
                "127077442639592750654187331744194691539",
                "124031150929166538110226749394651773023",
                "284903775854258554480629260751814976223",
                "309273998830710011178705223494755779564",
                "84631180735340755823180062132861391637",
                "339631979007708136365531932306031144234",
                "281495365852892570635716828475872123957",
                "14986263903821859995467086800199636871",
                "49471467178511156521801688028948033764",
                "224089778259474872981547778289879113250"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-75627-138207b0",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
        "target": {
            "file": "src/test/java/loophole/mvc/base/DispatcherServletTest.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "214249371367930942594964606302797771595",
            "length": 287
        },
        "id": "CVE-2026-75627-159a00e3",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
        "target": {
            "file": "src/test/java/loophole/mvc/base/DispatcherServletTest.java",
            "function": "unmatchedForwardOnAnAlreadyCommittedResponseDoesNotAttemptSendError"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "316893996809433818343677667514016869549",
            "length": 759
        },
        "id": "CVE-2026-75627-1eed02b3",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
        "target": {
            "file": "src/main/java/io/bastillion/manage/socket/SecureShellWS.java",
            "function": "onOpen"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "106357714796329960548325237575942975660",
            "length": 351
        },
        "id": "CVE-2026-75627-20cac6fd",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
        "target": {
            "file": "src/test/java/loophole/mvc/base/DispatcherServletTest.java",
            "function": "forwardsToViewReturnedByController"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "127306233333222486834294375910028442843",
            "length": 619
        },
        "id": "CVE-2026-75627-23fa6d49",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
        "target": {
            "file": "src/test/java/loophole/mvc/base/BaseKontrollerExecuteTest.java",
            "function": "handlesBracketedParameterKeyMissingClosingBracket"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "147238379328134725715962947012201896780",
            "length": 404
        },
        "id": "CVE-2026-75627-24b46fbd",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
        "target": {
            "file": "src/test/java/loophole/mvc/base/BaseKontrollerExecuteTest.java",
            "function": "invokesControllerMethodMatchingPathAndHttpMethod"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "177035832814905769811440062199463092983",
            "length": 686
        },
        "id": "CVE-2026-75627-2cc79f16",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
        "target": {
            "file": "src/test/java/loophole/mvc/base/BaseKontrollerExecuteTest.java",
            "function": "skipsExecuteMethodAndReturnsValidationInputWhenValidateAddsFieldError"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "109458046077551543042191136146781242403",
                "201756178357233716193341110171152063533",
                "255414789537943351686107116236264447545",
                "329251305714051304880803414368441806762",
                "173775682591512703659617132600808246077",
                "124462769918480878181391870694976718142",
                "120869908351195111535749713335822974328",
                "171066037737503494257648033984016339645",
                "276557223366971315029625182492060756036",
                "218317338785410685162438116231160439020",
                "61854763406717276289353362384968544908",
                "306322855909946489420739023678367136287",
                "121115579156419155521494975072162644628",
                "57211717095011236826982424535325491591",
                "248605509258165324149745461895145460968",
                "223608342197697156610291408217378992209",
                "335284243546497760686616977920301585414",
                "75531605491199870116545700751011721471",
                "25681108396694273617860619244050133219",
                "177980242591394377863159481782574722962",
                "183354044868842639282564317384669573862",
                "47478914520778998592266946933012562892",
                "281487404892005538961911137656080022732",
                "25126981143028120667437849936398443190",
                "85485291442291985816005005335934691605",
                "338487092976674953434466819600717604981",
                "163603051227968934520136302513477549396",
                "58959799412372027647168117379873398819",
                "137762091617009465134933466701099274302",
                "98570063401079778796971222065779481260",
                "127226036359298155912779223592371813994",
                "253818299148757184144907339274343034027"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-75627-4dea18f6",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
        "target": {
            "file": "src/test/java/loophole/mvc/base/BaseKontrollerExecuteTest.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "311219038643382896495680625200976993598",
                "47698881658597565719228310305628932306",
                "252014944294223245939017951913993997989",
                "126635173006550800463132290207961008754",
                "269164831292645585197171117041528687902",
                "197772108202444248545787542955706231696",
                "79473884910578009305889084996122308610",
                "316869590091515561158023153230911000418",
                "108617384494726934982889180642701277411",
                "304573078646780258203538040715213388937",
                "308743202808405983992992723397615561148",
                "73683559406046979779831784757339459578",
                "254677163302501661873200468726021430580",
                "241685096483929967820862104994209174621",
                "189406428705736960801901789778537147122",
                "245248132350394207111077370891926009238",
                "286958945159549554525702423258520320946",
                "199710990182788164166446614217627291156",
                "35667145348277290151539964999866141297",
                "32183657053522484135273057903277526996",
                "13400829124019663126883112940927779550",
                "23597743900231912314982926767401547744",
                "178710742005336651830020800934757495128",
                "194194620634857213645548129561820264435"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-75627-56977a97",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
        "target": {
            "file": "src/main/java/io/bastillion/manage/control/LoginKtrl.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "146737148374655700146655064475959288831",
            "length": 667
        },
        "id": "CVE-2026-75627-5a53de75",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
        "target": {
            "file": "src/test/java/loophole/mvc/base/BaseKontrollerExecuteTest.java",
            "function": "populatesMapModelFieldFromBracketedParameterName"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "142703019316893694888284346272216022115",
                "152476493396534406812848274480157900618",
                "144984276348153896436124458534171938631",
                "151968349311916619167976416673914245712"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-75627-a0859b5f",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
        "target": {
            "file": "src/main/java/io/bastillion/common/filter/AuthFilter.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "325798657237994420723036345712116991670",
            "length": 653
        },
        "id": "CVE-2026-75627-a4194c5a",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
        "target": {
            "file": "src/test/java/loophole/mvc/base/BaseKontrollerExecuteTest.java",
            "function": "populatesModelAnnotatedFieldsFromRequestParametersAndBack"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "205914588541578032264324270991299748958",
            "length": 517
        },
        "id": "CVE-2026-75627-a540f273",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
        "target": {
            "file": "src/test/java/loophole/mvc/base/BaseKontrollerExecuteTest.java",
            "function": "handlesAdversarialBracketedParameterNameWithoutQuadraticSlowdown"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "112650395610541313216915703364468428248",
            "length": 2166
        },
        "id": "CVE-2026-75627-b334f1ef",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
        "target": {
            "file": "src/main/java/io/bastillion/manage/control/LoginKtrl.java",
            "function": "loginSubmit"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "39108634396453363512137112979241752071",
                "128987413345316311544954419155197865394",
                "64111268182138392738556808458078611991",
                "120095997768640523963887229506429590879",
                "244096217942773172606319876428155022838",
                "44676050019751309409495348030752280507",
                "339611586861617160344730906988165499145",
                "147390796916144036899071348745071319026",
                "334047802613962569673657691212767711818",
                "134474189669874576389022316860597117587",
                "218688610510947085752981251620125603811",
                "181764694941146801550711911365220564514",
                "119817979076503306512270852971974700335",
                "128173374995324360841757187318854555942",
                "203859751780617765799070683020660972116",
                "85519590371758540358615618576583530167"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-75627-b54acc37",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
        "target": {
            "file": "src/main/java/io/bastillion/manage/socket/SecureShellWS.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "88213556873673919973080127743824251516",
            "length": 492
        },
        "id": "CVE-2026-75627-c4b810fc",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
        "target": {
            "file": "src/test/java/loophole/mvc/base/DispatcherServletTest.java",
            "function": "redirectsAndAppendsCsrfTokenFromSession"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "189272480504082291782609967122300056959",
                "4124558495824483303001020805867138664",
                "80724125710690664276350461460771780234",
                "37560194970812787784940391341690862658"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-75627-ea157047",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
        "target": {
            "file": "src/main/java/loophole/mvc/base/BaseKontroller.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "243236184376157731735476385311330097618",
            "length": 295
        },
        "id": "CVE-2026-75627-f13096b2",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
        "target": {
            "file": "src/test/java/loophole/mvc/base/DispatcherServletTest.java",
            "function": "unmatchedUriWithNothingWrittenYetSends404"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "110396338135353324027329242859418443300",
                "212669928949245496127551652673956782213",
                "322345668627863902057464920279574717913",
                "268615777942151801307763125172946932533",
                "170088811096970146724631828807205786969",
                "188215320482007166676983989510814338081",
                "125004997967838587072287312125187596621",
                "91639420279880476202095184273918862812",
                "114889614032053956236398171709186583293",
                "324785196232598550360870832518671267550",
                "151085070162374444832606377514819015107",
                "157764284741877913447068427559108794246",
                "168461245703009204965585952540742270814",
                "302202436563573877330020349736517619940",
                "25995584182825028914933506050716562451",
                "85364862415870027695857254579943850967"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-75627-f9a35209",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8",
        "target": {
            "file": "src/test/java/io/bastillion/common/filter/AuthFilterTest.java"
        }
    }
]
vanir_signatures_modified
"2026-08-20T09:52:36Z"