Back to VulnFeed / CVE-2026-42864
root@hackertop:~/vulnfeed/CVE-2026-42864#
CVE-2026-42864 HIGH CVE ⚠ Unpatched · Zero-day◉ PoC 公开 Lifecycle 4/7

ManoManoTech firefighter-incident up to 0.0.53 jira_bot httpx.get missing authentication

firefighter-incident 2d ago Impact pending confirmation
LIFECYCLE
8.4 CVSS
Vulnerability Detail Mitigation Lifecycle CVSS Assessment
Vulnerability Description
A vulnerability classified as critical has been found in ManoManoTech firefighter-incident up to 0.0.53. Affected is the function httpx.get of the file /api/v2/firefighter/raid/jira_bot. Upgrading to version 0.0.54 eliminates this vulnerability.
Root Cause Analysis
CWE is classifying the issue as CWE-306. The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Impact: This is going to have an impact on confidentiality, integrity, and availability.

Countermeasure: Upgrading to version 0.0.54 eliminates this vulnerability.
Validation (PoC/EXP) - Looking for Contributors
No public PoC yet

Public validation traces already exist. Community contributors can extend them with richer reproduction content.

Contribute Your PoC/EXP
Log in to contribute PoC/EXP content. Log in
Back to VulnFeed
CVE-2026-42864 · CVSS 8.4 · Active Threat