CVE-2026-39908 PUBLISHED

OpenBullet2 0.3.2 NTLMv2 Hash Disclosure via UNC Path Proxy Source

Assigner: VulnCheck
Reserved: 07.04.2026 Published: 08.06.2026 Updated: 08.06.2026

OpenBullet2 through version 0.3.2 on Windows contains a credential disclosure vulnerability that allows remote attackers to capture the NTLMv2 hash of the process user by configuring a job proxy source with a UNC path pointing to an attacker-controlled server. When the job starts, the application attempts to load proxies from the UNC path, triggering an SMB authentication attempt that discloses the NTLMv2 hash, which can then be relayed or cracked offline.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor openbullet
Product openbullet2
Versions Default: affected
  • affected from 0 to 0.3.2 (incl.)

Credits

  • Maksim Rogov finder
  • VulnCheck finder

References

Problem Types

  • Insufficiently Protected Credentials CWE