Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers can access administrative controllers to read user listings, create manager accounts, and register managed systems, gaining control over SSH access to the managed fleet.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
Bastillion, an SSH key management platform, contains a critical authentication bypass vulnerability in its controller dispatcher that fails to properly validate request URI paths. By prepending arbitrary path segments to requests, unauthenticated attackers can circumvent authentication filters entirely, gaining unauthorized access to sensitive administrative functions. This vulnerability is particularly dangerous because it allows attackers to enumerate user listings, create new manager accounts with elevated privileges, and register additional systems into the managed fleet—effectively taking control of SSH access across an entire infrastructure. Any organization using Bastillion for centralized SSH key management faces immediate risk of complete credential compromise and lateral movement capabilities across their entire managed system inventory.
While this CVE maps to CWE-288 (Authentication Bypass Using an Alternate Path or Channel), detection requires behavioral analysis around request routing anomalies and privilege escalation patterns. Casky practitioners would identify this attack through skills focused on detecting unusual authentication failures followed by successful administrative actions, path manipulation attempts in web application logs, and anomalous account creation events—particularly the rapid provisioning of manager accounts from previously unauthorized network segments. Although MITRE ATT&CK techniques aren't formally mapped for this CVE, the exploitation pattern aligns with techniques like T1078 (Valid Accounts) and T1190 (Exploit Public-Facing Application). Practitioners using Casky's extended reasoning capabilities would correlate web dispatcher logs showing path prefix anomalies with downstream lateral movement and credential access activities, surfacing the authentication bypass before full system compromise occurs.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-75627. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation