CVE intelligence

CVE-2026-86242

Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins whe

Published 2026-09-06 · CVSS

high

NIST record