{"id":"CVE-2026-90481","title":"In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an authentication bypass can occur via an alternate path or channel.","summary":"In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an authentication bypass can occur via an alternate path or channel.","severity":"critical","cvss":9.2,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L","cwe":["CWE-288"],"vendor":"PortSwigger","product":"Burp Suite DAST","affected":["burp_suite_dast >= 2021.11 < 2026.8"],"published":"2026-09-24","updated":"2026-09-24","sourceUpdated":"2026-09-24T21:08:22.573","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90481","references":[{"url":"https://portswigger.net/burp/releases/dast-2026-8","label":"cve@mitre.org"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-24T14:55:22.193962Z"},"cvssSource":"cna","ingestedAt":"2026-09-24T15:45:56.649Z","slug":"CVE-2026-90481","body":"## Overview\n\nIn PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an authentication bypass can occur via an alternate path or channel.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":51,"depthScoreParts":{"impact":50.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}