Remote Code Execution Vulnerability in Bifrost HTTP Transport by Maximhq
CVE-2026-86242

8.1HIGH

Key Information:

Vendor

Maximhq

Status
Vendor
CVE Published:
6 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-86242?

Bifrost HTTP Transport prior to version 2.0.0 has a vulnerability that allows unauthenticated attackers to exploit custom plugins via an HTTP URL. By sending a crafted POST request to /api/plugins with management authentication disabled, the system may incorrectly process a malicious plugin path. This can lead to remote code execution due to the incorrect handling of HTTP-prefixed paths as download URLs. It's crucial to apply the fix available in Bifrost HTTP Transport 2.0.0 to mitigate the risk of unauthorized access and code execution on affected systems. Attackers must match the hosting environment's specific configurations to exploit this vulnerability, highlighting its complexity.

Affected Version(s)

Bifrost Linux 0 < 2.0.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Or Peles
JFrog Security Research
.