CVE-2026-42864 - FireFighter: Unauthenticated SSRF in Raid jira_bot endpoint allows IAM credential theft
CVE ID :CVE-2026-42864 Published : May 11, 2026, 6:19 p.m. | 46 minutes ago Description :FireFighter is an incident management application. Prior to 0.0.54, the POST /api/v2/firefighter/raid/jira_bot endpoint (CreateJiraBotView) is reachable without authentication (permission_classes = [permis
ORIGINAL SOURCE →via CVE Feed Latest
ADVERTISEMENT
⚡ STAY AHEAD
Events like this, convergence-verified across 689 sources, land in your inbox every Sunday. Free.
GET THE SUNDAY BRIEFING →RELATED · cyber
- [CYBER] Google says hackers used AI to exploit ‘zero-day’ flaw
- [CYBER] CVE-2026-42871 - WeGIA: Error Handling familiar_docfamiliar
- [CYBER] Google says hacker used Mythos-like AI for zero-day exploit
- [CYBER] CVE-2026-42866 - Tookie: Arbitrary file write via path traversal in -u username / -U userfile output filename
- [CYBER] CVE-2026-8305 - OpenClaw bluebubbles Webhook monitor.ts handleBlueBubblesWebhookRequest improper authentication
- [CYBER] CVE-2026-7308 - Nexus Repository 3 - Stored Cross-Site Scripting (XSS) via HTML Browse Page