{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/ssh-gateway/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-75627"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Bastillion (5.1.0)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","authentication-bypass","ssh-gateway"],"_cs_type":"advisory","_cs_vendors":["Bastillion"],"content_html":"\u003cp\u003eBastillion, an open-source SSH gateway, contains a critical authentication bypass vulnerability (CVE-2026-75627) in its controller dispatcher logic. The vulnerability, rooted in improper validation of request URI paths within the \u003ccode\u003eBaseKontroller.java\u003c/code\u003e component, allows an unauthenticated attacker to bypass authentication filters by prefixing legitimate administrative request URIs with arbitrary path segments.\u003c/p\u003e\n\u003cp\u003eBy successfully navigating this dispatcher flaw, an attacker gains unauthorized access to administrative functions. This access allows the actor to read sensitive user listings, create new manager accounts with elevated privileges, and register new managed systems within the Bastillion environment. Given Bastillion's role as a gateway for SSH access, this exploit grants attackers potential control over the entire managed server fleet. The vulnerability affects all versions of Bastillion up to and including 5.1.0. Defenders must prioritize patching, as this vulnerability allows complete compromise of the Bastillion instance without prior authentication.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify the presence of Bastillion and its administrative endpoints.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP request targeting an administrative controller (e.g., /user/list or /manager/create).\u003c/li\u003e\n\u003cli\u003eAttacker prepends an arbitrary path segment to the URI, triggering the flaw in the dispatcher's authentication filter logic.\u003c/li\u003e\n\u003cli\u003eThe Bastillion application fails to validate the manipulated URI path and treats the request as authorized.\u003c/li\u003e\n\u003cli\u003eAttacker executes the administrative function, such as creating a new privileged manager account.\u003c/li\u003e\n\u003cli\u003eAttacker authenticates with the newly created manager account.\u003c/li\u003e\n\u003cli\u003eAttacker uses the administrative interface to register additional managed systems or modify existing configurations.\u003c/li\u003e\n\u003cli\u003eAttacker leverages the compromised gateway to initiate unauthorized SSH connections to the managed backend infrastructure.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-75627 results in a complete compromise of the Bastillion SSH gateway. An attacker can create administrative accounts, gain visibility into user data, and establish unauthorized persistence within the infrastructure. This allows for the exfiltration of credentials or the execution of arbitrary commands on the managed SSH fleet, potentially leading to widespread lateral movement and system takeover.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade Bastillion to a patched version beyond 5.1.0 to resolve CVE-2026-75627.\u003c/li\u003e\n\u003cli\u003eImplement strict network-level access control lists (ACLs) to restrict access to the Bastillion administrative interface to known management subnets.\u003c/li\u003e\n\u003cli\u003eEnable web application firewall (WAF) rules to detect and block requests containing irregular path structures or suspicious path prefixes aimed at administrative controllers.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rules below to monitor for attempts to access internal administrative controllers from unauthorized or unauthenticated sources.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-18T12:51:22Z","date_published":"2026-08-18T12:51:22Z","id":"https://feed.craftedsignal.io/briefs/2026-08-bastillion-auth-bypass/","summary":"An authentication bypass vulnerability (CVE-2026-75627) in Bastillion versions 5.1.0 and earlier allows unauthenticated attackers to access administrative controllers via path prefix manipulation, enabling full control over managed SSH infrastructure.","title":"Authentication Bypass in Bastillion via Path Prefix Misrouting","url":"https://feed.craftedsignal.io/briefs/2026-08-bastillion-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Ssh-Gateway","version":"https://jsonfeed.org/version/1.1"}