← Vulnerability feed

Vulnerability record · CVE-2022-25237 · published 2 June 2022

CVE-2022-25237: Bonita Web RestAPIAuthorizationFilter auth bypass via URL suffix

Bonitasoft · Bonita Web

Bonita Web 2021.2 uses an overly broad exclude pattern in its RestAPIAuthorizationFilter, so appending ;i18ntranslation or /../i18ntranslation/ to a URL lets unprivileged users reach privileged API endpoints. Because those privileged API actions can be abused, the bypass can escalate to remote code execution.

9.8 CVSS 3.1 Critical EPSS 56% · top 1.0%
9.8CVSS 3.1 base score, v2 7.5
56%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Bonita Web 2021.2 is affected by a authentication/authorization bypass vulnerability due to an overly broad exclude pattern used in the RestAPIAuthorizationFilter. By appending ;i18ntranslation or /../i18ntranslation/ to the end of a URL, users with no privileges can access privileged API endpoints. This can lead to remote code execution by abusing the privileged API actions.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or interaction required, and the bypass can lead to remote code execution.

What it is

Bonita Web 2021.2 uses an overly broad exclude pattern in its RestAPIAuthorizationFilter, so appending ;i18ntranslation or /../i18ntranslation/ to a URL lets unprivileged users reach privileged API endpoints. Because those privileged API actions can be abused, the bypass can escalate to remote code execution.

Impact

An attacker with no privileges gains access to privileged API functionality and can potentially execute remote code on the server.

Attack surface

Reachable over the network through crafted HTTP requests to the REST API; the CVSS vector shows no authentication and no user interaction required.

Exploitation

Not listed in CISA KEV, but EPSS is 0.56449 (99th percentile) and references carry an Exploit tag, indicating public exploit detail exists.

What to do

  • Upgrade Bonita Web to a version where the RestAPIAuthorizationFilter exclude pattern is fixed; the record does not name fixed versions, so confirm with Bonitasoft.
  • Restrict network access to the Bonita REST API to trusted clients only.
  • Review and tighten URL filter/authorization rules so path suffixes such as ;i18ntranslation and /../ cannot bypass checks.
  • Audit accounts and API actions for unexpected privileged calls and remove unnecessary privileges.

Detection

  • Search web/proxy logs for requests containing ;i18ntranslation or /../i18ntranslation/ in the URL.
  • Alert on privileged REST API calls made by low-privilege or unauthenticated sessions.
  • Monitor for unusual API actions that could lead to code execution, such as script or process-related endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-25237 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2022-25237), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.