Yeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, allowing users with read access to delete access control relationships. Attackers can revoke the owner's grant and permanently lock legitimate owners out of objects.
References
Configurations
No configuration.
History
16 Sep 2026, 21:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-09-16 21:17
Updated : 2026-09-17 14:17
NVD link : CVE-2026-92783
Mitre link : CVE-2026-92783
CVE.ORG link : CVE-2026-92783
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
