By vendor
Bootimus vulnerabilities
Known CVEs affecting Bootimus products, prioritized by severity, with SEC.co remediation and detection guidance.
1 published vulnerability
- CVE-2026-56115HIGH 8.8
Bootimus versions up to 0.1.70 suffer from a privilege escalation vulnerability that allows low-privileged authenticated users to perform administrative actions without proper authorization. The flaw exists in the JWT token validation logic, which checks whether a user is logged in and has an active account, but neglects to verify whether that user holds administrator rights. An attacker with legitimate access can exploit this gap to create new admin accounts or reset existing administrator passwords, effectively taking over the entire Bootimus server. This is particularly dangerous because Bootimus serves boot menus and installation scripts to PXE clients—meaning an attacker could modify the operating system images or scripts deployed across your infrastructure.