Remote Code Execution Vulnerability in Bifrost HTTP Transport by Maximhq
CVE-2026-86242
Key Information:
Badges
What is CVE-2026-86242?
Bifrost HTTP Transport prior to version 2.0.0 has a vulnerability that allows unauthenticated attackers to exploit custom plugins via an HTTP URL. By sending a crafted POST request to /api/plugins with management authentication disabled, the system may incorrectly process a malicious plugin path. This can lead to remote code execution due to the incorrect handling of HTTP-prefixed paths as download URLs. It's crucial to apply the fix available in Bifrost HTTP Transport 2.0.0 to mitigate the risk of unauthorized access and code execution on affected systems. Attackers must match the hosting environment's specific configurations to exploit this vulnerability, highlighting its complexity.
Affected Version(s)
Bifrost Linux 0 < 2.0.0
References
CVSS V3.1
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
