High severity8.8NVD Advisory· Published Jun 8, 2026· Updated Jun 9, 2026
CVE-2026-25856
CVE-2026-25856
Description
OpenBullet2 through version 0.3.2 contains an authenticated remote code execution vulnerability that allows authenticated users to execute arbitrary C# code on the server host by creating or modifying job configurations. Attackers can leverage the plain C# execution mode, which lacks reference filtering or API restrictions, to access the file system, spawn processes, and invoke arbitrary .NET APIs as the process user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=0.3.2
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.