THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-86242 (HIGH 8.1) — Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled (the default, governance.auth_config.is_enabled=false). The shared-object loader treats an http-pref

[NVD] CVE-2026-86242 (HIGH 8.1) — Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled (the default, governance.auth_config.is_enabled=false). The shared-object loader treats an http-pref

mednvdPublished 2026-09-06

CVE-2026-86242 CVSS: 8.1 HIGH Published: 2026-09-06T12:17:15.583

Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled (the default, governance.auth_config.is_enabled=false). The shared-object loader treats an http-prefixed path as a download URL, writes the body to a temp

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86242