OpenBullet2 through version 0.3.2 contains an authenticated remote code execution vulnerability that allows authenticated users to execute arbitrary C# code on the server host by creating or modifying job configurations. Attackers can leverage the plain C# execution mode, which lacks reference filtering or API restrictions, to access the file system, spawn processes, and invoke arbitrary .NET APIs as the process user.
Metrics
Affected Vendors & Products
References
History
Mon, 08 Jun 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenBullet2 through version 0.3.2 contains an authenticated remote code execution vulnerability that allows authenticated users to execute arbitrary C# code on the server host by creating or modifying job configurations. Attackers can leverage the plain C# execution mode, which lacks reference filtering or API restrictions, to access the file system, spawn processes, and invoke arbitrary .NET APIs as the process user. | |
| Title | OpenBullet2 0.3.2 Authenticated RCE via Job Configuration Interface | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-08T18:48:33.862Z
Reserved: 2026-02-06T19:12:03.462Z
Link: CVE-2026-25856
No data.
Status : Received
Published: 2026-06-08T17:16:41.523
Modified: 2026-06-08T17:16:41.523
Link: CVE-2026-25856
No data.
OpenCVE Enrichment
Updated: 2026-06-08T18:30:16Z