← Vulnerability feed

Vulnerability record · CVE-2026-24124 · published 22 January 2026

CVE-2026-24124: Linuxfoundation dragonfly missing authentication for critical function vulnerability

Linuxfoundation · Dragonfly

Dragonfly is an open source P2P-based file distribution and image acceleration system. In versions 2.4.1-rc.0 and below, the Job API endpoints (/api/v1/jobs) lack JWT authentication middleware and RBAC authorization checks in the routing configuration. This allows any unauthenticated user with access to the Manager API to view, update and delete jobs. The issue is fixed in version 2.4.1-rc.1.

8.9 CVSS 4.0 High EPSS 0.79% · top 45.4% CWE-306 · Missing authentication for critical function
8.9CVSS 4.0 base score
0.79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Dragonfly is an open source P2P-based file distribution and image acceleration system. In versions 2.4.1-rc.0 and below, the Job API endpoints (/api/v1/jobs) lack JWT authentication middleware and RBAC authorization checks in the routing configuration. This allows any unauthenticated user with access to the Manager API to view, update and delete jobs. The issue is fixed in version 2.4.1-rc.1.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-24124 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-27584Linuxfoundation dragonfly hard-coded credentials vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) a…EPSS 34%7.7CVE-2025-59353Linuxfoundation dragonfly improper certificate validation vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, a peer can obtain a valid TLS certificate for …EPSS 0.23%7.7CVE-2025-59345Linuxfoundation dragonfly missing authentication for critical function vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The /api/v1/jobs and /preheats endpoints in Ma…EPSS 0.38%6.9CVE-2025-59352Linuxfoundation dragonfly path traversal vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the gRPC API and HTTP APIs allow peers to send…EPSS 0.73%5.5CVE-2025-59354Linuxfoundation dragonfly vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the DragonFly2 uses a variety of hash function…EPSS 0.16%5.5CVE-2025-59410Linuxfoundation dragonfly missing encryption vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the code in the scheduler for downloading a ti…EPSS 0.14%5.5CVE-2025-59348Linuxfoundation dragonfly vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the processPieceFromSource method does not upd…EPSS 0.36%5.5CVE-2025-59346Linuxfoundation dragonfly server-side request forgery (ssrf) vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. Versions prior to 2.1.0 contain a server-side request forgery …EPSS 0.25%

Source: NIST National Vulnerability Database (record CVE-2026-24124), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.