CVE-2026-85213

Kill Bill through 0.24.21 fails to enforce permission annotations on several AdminResource endpoints including getQueueEntries, invalidatesCache, and putOutOfRotation. Authenticated users with minimal account:read permissions can read internal queues, flush server caches, and disable the server by putting the host out of rotation.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-03 15:17

Updated : 2026-09-10 15:53


NVD link : CVE-2026-85213

Mitre link : CVE-2026-85213

CVE.ORG link : CVE-2026-85213


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization