CVE-2026-90481: Portswigger Burp Suite Dast
Critical severity, CVSS 9.2. EPSS: 0.3% chance of exploitation in the next 30 days.
In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an authentication bypass can occur via an alternate path or channel.
Affected products
- Portswigger Burp Suite Dast: from 2021.11, before 2026.8 (fixed in 2026.8)
Published 2026-09-24. Last modified 2026-09-24.