CVE-2026-92780

KnowStreaming through 3.4.1 fails to enforce role-based access control on REST API endpoints, allowing any authenticated user to access protected functionality. Attackers can call identity-management endpoints to create administrator accounts or grant themselves administrative privileges without proper authorization.
Configurations

No configuration.

History

17 Sep 2026, 16:18

Type Values Removed Values Added
References () https://github.com/didi/KnowStreaming/issues/1263 - () https://github.com/didi/KnowStreaming/issues/1263 -

16 Sep 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-09-16 21:17

Updated : 2026-09-17 16:18


NVD link : CVE-2026-92780

Mitre link : CVE-2026-92780

CVE.ORG link : CVE-2026-92780


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization