HIGH🇵🇱 Wersja polska

CVE-2026-24124

CVSS 8.9v4.0pub. 2026-01-22upd. 2026-02-26

Dragonfly is an open source P2P-based file distribution and image acceleration system. In versions 2.4.1-rc.0 and below, the Job API endpoints (/api/v1/jobs) lack JWT authentication middleware and RBAC authorization checks in the routing configuration. This allows any unauthenticated user with access to the Manager API to view, update and delete jobs. The issue is fixed in version 2.4.1-rc.1.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Linuxfoundation Dragonfly

    APP
    Linuxfoundation
    2.4.1< 2.4.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-27584CRITICAL9.8PL ✓same product

Dragonfly: hardkodowany klucz JWT umożliwia pominięcie uwierzytelnienia

CVE-2025-59345HIGH7.7same product

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The /ap...

CVE-2025-59353HIGH7.7same product

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, a peer ...

CVE-2025-59348MEDIUM5.5same product

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the pro...

CVE-2025-59346MEDIUM5.5same product

Dragonfly is an open source P2P-based file distribution and image acceleration system. Versions prior to 2.1.0...