CVE Feed

    Dashboard / CVE / CVE-2026-24124

    CVE-2026-24124

    Dragonfly is an open source P2P-based file distribution and image acceleration system. In versions 2.4.1-rc.0 and below, the Job API endpoints (/api/v1/jobs) lack JWT authentication middleware and RBAC authorization checks in the routing configuration. This allows any unauthenticated user with access to the Manager API to view, update and delete jobs. The issue is fixed in version 2.4.1-rc.1.

    Published:Jan 22, 2026
    Last Modified:Apr 18, 2026
    EPS:Jan 22, 2026
    EPSS Score:0.00114
    CVSS Score:9.8

    Affected Products

    Vendor
    Dragonflyoss
    Product
    Dragonfly2
    Vendor
    Linuxfoundation
    Product
    Dragonfly

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High