KnowStreaming through 3.4.1 fails to enforce role-based access control on REST API endpoints, allowing any authenticated user to access protected functionality. Attackers can call identity-management endpoints to create administrator accounts or grant themselves administrative privileges without proper authorization.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | KnowStreaming through 3.4.1 fails to enforce role-based access control on REST API endpoints, allowing any authenticated user to access protected functionality. Attackers can call identity-management endpoints to create administrator accounts or grant themselves administrative privileges without proper authorization. | |
| Title | KnowStreaming through 3.4.1 Missing Authorization on the REST API | |
| First Time appeared |
Knowstreaming Project
Knowstreaming Project knowstreaming |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:knowstreaming_project:knowstreaming:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Knowstreaming Project
Knowstreaming Project knowstreaming |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T20:32:38.224Z
Reserved: 2026-09-16T19:22:53.441Z
Link: CVE-2026-92780
No data.
Status : Received
Published: 2026-09-16T21:17:26.987
Modified: 2026-09-16T21:17:26.987
Link: CVE-2026-92780
No data.
OpenCVE Enrichment
No data.
Weaknesses