{"id":"CVE-2026-75627","summary":"Bastillion Authentication Bypass via Path-Prefix Routing Mismatch","details":"Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers can access administrative controllers to read user listings, create manager accounts, and register managed systems, gaining control over SSH access to the managed fleet.","modified":"2026-08-20T09:52:36.441782Z","published":"2026-08-18T10:46:54.674Z","database_specific":{"cwe_ids":["CWE-288"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75627.json","cna_assigner":"VulnCheck"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75627.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75627"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/bastillion-authentication-bypass-via-path-prefix-routing-mismatch"},{"type":"REPORT","url":"https://github.com/bastillion-io/Bastillion/issues/669"},{"type":"FIX","url":"https://github.com/bastillion-io/Bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8"},{"type":"PACKAGE","url":"https://github.com/bastillion-io/Bastillion"},{"type":"ARTICLE","url":"https://github.com/bastillion-io/Bastillion/blob/master/src/main/java/loophole/mvc/base/BaseKontroller.java"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/bastillion-io/bastillion","events":[{"introduced":"0"},{"fixed":"d759fb686a1a097b1b026e286fd9b20e5ba349c8"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"5.1.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v5.1.0","v5.0.1","v5.0.0","v4.0.1","v4.0.0","v3.15.00","v3.14.0","v3.13.00","v3.12.02","v3.12.01","v3.12.00","v3.11.01","v3.10.00","v3.09.00","v3.08.01","v3.08.00","v3.06.04","v3.06.03","v3.06.02","v3.06.01","v3.06.00","v3.05.01","v3.02.00","v3.01.00","v3.00.03","v3.00.02","v3.00.01","v3.00.00","v2.90.03","v2.90.02","v2.90.01","v2.90.00","v2.89.00","v2.88.01","v2.88.00","v2.87.01","v2.87.00","v2.86.00","v2.85.03","v2.85.02","v2.85.01","v2.84.01","v2.84.00","v2.83.02","v2.83.01","v2.83.00","v2.82.00","v2.80.00","v2.75.00","v2.73.02","v2.73.01","v2.73.00","v2.70.01","v2.60.00","v2.50.02","v2.50.01","v2.50.00","v2.17.01","v2.17.00","v2.16.00","v2.15.27","v2.15.26","v2.15.25","v2.15.20","v2.15.10","v2.15.00","v2.12.00","v2.11.05","v2.11.00","v2.10.03","v2.10.02","v2.10.01","v2.10.00","v2.06.00","v2.05.02","v2.05.01","v2.05.00","v2.02.02","v2.02.01","v2.02.00","v2.01.00","v2.00.00","v1.08.54","v1.08.53","v1.08.52","v1.08.51","v1.08.50","v1.08.40","v1.08.30","v1.08.20"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75627.json","vanir_signatures_modified":"2026-08-20T09:52:36Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"302047522726612019582120512413827961495","length":625},"id":"CVE-2026-75627-01858233","signature_type":"Function","signature_version":"v1","source":"https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8","target":{"file":"src/test/java/loophole/mvc/base/BaseKontrollerExecuteTest.java","function":"stripsQuotesFromBracketedParameterKey"}},{"target":{"file":"src/test/java/loophole/mvc/base/BaseKontrollerExecuteTest.java","function":"doesNotInvokeControllerMethodWhenHttpMethodDoesNotMatch"},"deprecated":false,"digest":{"function_hash":"199258960994840768801617323500969597505","length":308},"id":"CVE-2026-75627-073a4332","signature_type":"Function","signature_version":"v1","source":"https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8"},{"deprecated":false,"digest":{"line_hashes":["193824396252684728063001484174684226534","197080244004145042948327157892127429773","166776754402698981237552379874307282761","170013315515999957247356211766833516164","153598416542175048614078520788800027471","35820544237400732462057694992544528135","127077442639592750654187331744194691539","124031150929166538110226749394651773023","284903775854258554480629260751814976223","309273998830710011178705223494755779564","84631180735340755823180062132861391637","339631979007708136365531932306031144234","281495365852892570635716828475872123957","14986263903821859995467086800199636871","49471467178511156521801688028948033764","224089778259474872981547778289879113250"],"threshold":0.9},"id":"CVE-2026-75627-138207b0","signature_type":"Line","signature_version":"v1","source":"https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8","target":{"file":"src/test/java/loophole/mvc/base/DispatcherServletTest.java"}},{"signature_version":"v1","source":"https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8","target":{"file":"src/test/java/loophole/mvc/base/DispatcherServletTest.java","function":"unmatchedForwardOnAnAlreadyCommittedResponseDoesNotAttemptSendError"},"deprecated":false,"digest":{"function_hash":"214249371367930942594964606302797771595","length":287},"id":"CVE-2026-75627-159a00e3","signature_type":"Function"},{"deprecated":false,"digest":{"function_hash":"316893996809433818343677667514016869549","length":759},"id":"CVE-2026-75627-1eed02b3","signature_type":"Function","signature_version":"v1","source":"https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8","target":{"file":"src/main/java/io/bastillion/manage/socket/SecureShellWS.java","function":"onOpen"}},{"digest":{"function_hash":"106357714796329960548325237575942975660","length":351},"id":"CVE-2026-75627-20cac6fd","signature_type":"Function","signature_version":"v1","source":"https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8","target":{"file":"src/test/java/loophole/mvc/base/DispatcherServletTest.java","function":"forwardsToViewReturnedByController"},"deprecated":false},{"target":{"file":"src/test/java/loophole/mvc/base/BaseKontrollerExecuteTest.java","function":"handlesBracketedParameterKeyMissingClosingBracket"},"deprecated":false,"digest":{"length":619,"function_hash":"127306233333222486834294375910028442843"},"id":"CVE-2026-75627-23fa6d49","signature_type":"Function","signature_version":"v1","source":"https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8"},{"deprecated":false,"digest":{"function_hash":"147238379328134725715962947012201896780","length":404},"id":"CVE-2026-75627-24b46fbd","signature_type":"Function","signature_version":"v1","source":"https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8","target":{"file":"src/test/java/loophole/mvc/base/BaseKontrollerExecuteTest.java","function":"invokesControllerMethodMatchingPathAndHttpMethod"}},{"source":"https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8","target":{"function":"skipsExecuteMethodAndReturnsValidationInputWhenValidateAddsFieldError","file":"src/test/java/loophole/mvc/base/BaseKontrollerExecuteTest.java"},"deprecated":false,"digest":{"function_hash":"177035832814905769811440062199463092983","length":686},"id":"CVE-2026-75627-2cc79f16","signature_type":"Function","signature_version":"v1"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8","target":{"file":"src/test/java/loophole/mvc/base/BaseKontrollerExecuteTest.java"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["109458046077551543042191136146781242403","201756178357233716193341110171152063533","255414789537943351686107116236264447545","329251305714051304880803414368441806762","173775682591512703659617132600808246077","124462769918480878181391870694976718142","120869908351195111535749713335822974328","171066037737503494257648033984016339645","276557223366971315029625182492060756036","218317338785410685162438116231160439020","61854763406717276289353362384968544908","306322855909946489420739023678367136287","121115579156419155521494975072162644628","57211717095011236826982424535325491591","248605509258165324149745461895145460968","223608342197697156610291408217378992209","335284243546497760686616977920301585414","75531605491199870116545700751011721471","25681108396694273617860619244050133219","177980242591394377863159481782574722962","183354044868842639282564317384669573862","47478914520778998592266946933012562892","281487404892005538961911137656080022732","25126981143028120667437849936398443190","85485291442291985816005005335934691605","338487092976674953434466819600717604981","163603051227968934520136302513477549396","58959799412372027647168117379873398819","137762091617009465134933466701099274302","98570063401079778796971222065779481260","127226036359298155912779223592371813994","253818299148757184144907339274343034027"]},"id":"CVE-2026-75627-4dea18f6"},{"deprecated":false,"digest":{"line_hashes":["311219038643382896495680625200976993598","47698881658597565719228310305628932306","252014944294223245939017951913993997989","126635173006550800463132290207961008754","269164831292645585197171117041528687902","197772108202444248545787542955706231696","79473884910578009305889084996122308610","316869590091515561158023153230911000418","108617384494726934982889180642701277411","304573078646780258203538040715213388937","308743202808405983992992723397615561148","73683559406046979779831784757339459578","254677163302501661873200468726021430580","241685096483929967820862104994209174621","189406428705736960801901789778537147122","245248132350394207111077370891926009238","286958945159549554525702423258520320946","199710990182788164166446614217627291156","35667145348277290151539964999866141297","32183657053522484135273057903277526996","13400829124019663126883112940927779550","23597743900231912314982926767401547744","178710742005336651830020800934757495128","194194620634857213645548129561820264435"],"threshold":0.9},"id":"CVE-2026-75627-56977a97","signature_type":"Line","signature_version":"v1","source":"https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8","target":{"file":"src/main/java/io/bastillion/manage/control/LoginKtrl.java"}},{"deprecated":false,"digest":{"function_hash":"146737148374655700146655064475959288831","length":667},"id":"CVE-2026-75627-5a53de75","signature_type":"Function","signature_version":"v1","source":"https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8","target":{"file":"src/test/java/loophole/mvc/base/BaseKontrollerExecuteTest.java","function":"populatesMapModelFieldFromBracketedParameterName"}},{"signature_version":"v1","source":"https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8","target":{"file":"src/main/java/io/bastillion/common/filter/AuthFilter.java"},"deprecated":false,"digest":{"line_hashes":["142703019316893694888284346272216022115","152476493396534406812848274480157900618","144984276348153896436124458534171938631","151968349311916619167976416673914245712"],"threshold":0.9},"id":"CVE-2026-75627-a0859b5f","signature_type":"Line"},{"deprecated":false,"digest":{"function_hash":"325798657237994420723036345712116991670","length":653},"id":"CVE-2026-75627-a4194c5a","signature_type":"Function","signature_version":"v1","source":"https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8","target":{"file":"src/test/java/loophole/mvc/base/BaseKontrollerExecuteTest.java","function":"populatesModelAnnotatedFieldsFromRequestParametersAndBack"}},{"deprecated":false,"digest":{"length":517,"function_hash":"205914588541578032264324270991299748958"},"id":"CVE-2026-75627-a540f273","signature_type":"Function","signature_version":"v1","source":"https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8","target":{"file":"src/test/java/loophole/mvc/base/BaseKontrollerExecuteTest.java","function":"handlesAdversarialBracketedParameterNameWithoutQuadraticSlowdown"}},{"source":"https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8","target":{"file":"src/main/java/io/bastillion/manage/control/LoginKtrl.java","function":"loginSubmit"},"deprecated":false,"digest":{"length":2166,"function_hash":"112650395610541313216915703364468428248"},"id":"CVE-2026-75627-b334f1ef","signature_type":"Function","signature_version":"v1"},{"id":"CVE-2026-75627-b54acc37","signature_type":"Line","signature_version":"v1","source":"https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8","target":{"file":"src/main/java/io/bastillion/manage/socket/SecureShellWS.java"},"deprecated":false,"digest":{"line_hashes":["39108634396453363512137112979241752071","128987413345316311544954419155197865394","64111268182138392738556808458078611991","120095997768640523963887229506429590879","244096217942773172606319876428155022838","44676050019751309409495348030752280507","339611586861617160344730906988165499145","147390796916144036899071348745071319026","334047802613962569673657691212767711818","134474189669874576389022316860597117587","218688610510947085752981251620125603811","181764694941146801550711911365220564514","119817979076503306512270852971974700335","128173374995324360841757187318854555942","203859751780617765799070683020660972116","85519590371758540358615618576583530167"],"threshold":0.9}},{"digest":{"function_hash":"88213556873673919973080127743824251516","length":492},"id":"CVE-2026-75627-c4b810fc","signature_type":"Function","signature_version":"v1","source":"https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8","target":{"file":"src/test/java/loophole/mvc/base/DispatcherServletTest.java","function":"redirectsAndAppendsCsrfTokenFromSession"},"deprecated":false},{"deprecated":false,"digest":{"line_hashes":["189272480504082291782609967122300056959","4124558495824483303001020805867138664","80724125710690664276350461460771780234","37560194970812787784940391341690862658"],"threshold":0.9},"id":"CVE-2026-75627-ea157047","signature_type":"Line","signature_version":"v1","source":"https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8","target":{"file":"src/main/java/loophole/mvc/base/BaseKontroller.java"}},{"signature_version":"v1","source":"https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8","target":{"file":"src/test/java/loophole/mvc/base/DispatcherServletTest.java","function":"unmatchedUriWithNothingWrittenYetSends404"},"deprecated":false,"digest":{"function_hash":"243236184376157731735476385311330097618","length":295},"id":"CVE-2026-75627-f13096b2","signature_type":"Function"},{"signature_version":"v1","source":"https://github.com/bastillion-io/bastillion/commit/d759fb686a1a097b1b026e286fd9b20e5ba349c8","target":{"file":"src/test/java/io/bastillion/common/filter/AuthFilterTest.java"},"deprecated":false,"digest":{"line_hashes":["110396338135353324027329242859418443300","212669928949245496127551652673956782213","322345668627863902057464920279574717913","268615777942151801307763125172946932533","170088811096970146724631828807205786969","188215320482007166676983989510814338081","125004997967838587072287312125187596621","91639420279880476202095184273918862812","114889614032053956236398171709186583293","324785196232598550360870832518671267550","151085070162374444832606377514819015107","157764284741877913447068427559108794246","168461245703009204965585952540742270814","302202436563573877330020349736517619940","25995584182825028914933506050716562451","85364862415870027695857254579943850967"],"threshold":0.9},"id":"CVE-2026-75627-f9a35209","signature_type":"Line"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}