HIGH
juicedata
CVE published 2026-07-02
CVE-2026-59092
The CVE-2026-59092 record describes an authentication bypass vulnerability in JuiceFS through version 1.3.1, which allows unauthenticated remote attackers to access sensitive debug and metrics endpoints. This vulnerability is rated HIGH with a CVSS score of 7. The issue was fixed in commit a46979c. The vulnerability enables attackers to request the /debug/pprof/cmdline endpoint to obtain the process comma [truncated]