CrushFTP Authentication Bypass Vulnerability

CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authenticate to any known or guessable user account (e.g., crushadmin), potentially leading to a full compromise.

Published 25 Aug 2026Updated 25 Aug 202648 sources
CVSS 9.8 ✓ VERIFIED REFERENCE△ CISA KEV

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.