CVE-2026-24124
CVE-2026-24124 is a critical-severity vulnerability in Linuxfoundation Dragonfly with a CVSS 3.x base score of 9.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-306.
Key facts
- Severity: Critical (CVSS 3.x base score 9.8)
- CVSS v4: 8.9
- EPSS exploit prediction: 1% (55th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-3805
- Weakness: CWE-306
- Affected product: Linuxfoundation Dragonfly
- Published:
- Last modified:
Description
Dragonfly is an open source P2P-based file distribution and image acceleration system. In versions 2.4.1-rc.0 and below, the Job API endpoints (/api/v1/jobs) lack JWT authentication middleware and RBAC authorization checks in the routing configuration. This allows any unauthenticated user with access to the Manager API to view, update and delete jobs. The issue is fixed in version 2.4.1-rc.1.
Frequently asked questions
- What is CVE-2026-24124?
- Dragonfly is an open source P2P-based file distribution and image acceleration system. In versions 2.4.1-rc.0 and below, the Job API endpoints (/api/v1/jobs) lack JWT authentication middleware and RBAC authorization checks in the routing configuration. This allows any unauthenticated user with access to the Manager API to view, update and delete jobs. The issue is fixed in version 2.4.1-rc.1.
- How severe is CVE-2026-24124?
- CVE-2026-24124 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2026-24124 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (55th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-24124?
- CVE-2026-24124 primarily affects Linuxfoundation Dragonfly. In total, 4 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2026-24124?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- Does CVE-2026-24124 have an EU (EUVD) identifier?
- Yes. CVE-2026-24124 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-3805.
- When was CVE-2026-24124 published?
- CVE-2026-24124 was published on 2026-01-22 and last updated on 2026-06-17.
References
- https://github.com/dragonflyoss/dragonfly/commit/9fb9a2dfde3100f32dc7f48eabee4c2b64eac55f
- https://github.com/dragonflyoss/dragonfly/security/advisories/GHSA-j8hf-cp34-g4j7
Affected products (4)
- cpe:2.3:a:linuxfoundation:dragonfly:*:*:*:*:*:go:*:*
- cpe:2.3:a:linuxfoundation:dragonfly:2.4.1:beta0:*:*:*:go:*:*
- cpe:2.3:a:linuxfoundation:dragonfly:2.4.1:beta1:*:*:*:go:*:*
- cpe:2.3:a:linuxfoundation:dragonfly:2.4.1:rc0:*:*:*:go:*:*
More vulnerabilities in Linuxfoundation Dragonfly
- CVE-2025-59352 — Critical (CVSS 9.8): Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the gRPC API and…
- CVE-2023-27584 — Critical (CVSS 9.8): Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native…
- CVE-2025-59345 — Critical (CVSS 9.1): Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The /api/v1/jobs…
- CVE-2025-59353 — High (CVSS 7.5): Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, a peer can…
- CVE-2025-59348 — High (CVSS 7.5): Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the…
- CVE-2025-59347 — Medium (CVSS 6.5): Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The Manager…
All CVEs affecting Linuxfoundation Dragonfly →
Other CWE-306 (Missing Authentication for Critical Function) vulnerabilities
- CVE-2026-63692 — Critical (CVSS 10.0): Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Critical Function…
- CVE-2026-63688 — Critical (CVSS 10.0): Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Missing Authentication for Critical…
- CVE-2026-103956 — Critical (CVSS 10.0): Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed…
- CVE-2026-53988 — Critical (CVSS 10.0): Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows…
- CVE-2026-85889 — Critical (CVSS 10.0): Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges…
- CVE-2026-92808 — Critical (CVSS 10.0): A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An…
Browse all CWE-306 (Missing Authentication for Critical Function) vulnerabilities →