PT-2026-94057 · Didi+1 · Knowstreaming

·

CVE-2026-92780

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions KnowStreaming versions prior to 3.4.2
Description Failure to enforce role-based access control on REST API endpoints allows any authenticated user to access protected functionality. This enables attackers to call identity-management endpoints to create administrator accounts or grant themselves administrative privileges without proper authorization.
Recommendations Update KnowStreaming to version 3.4.2 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92780

Affected Products

Knowstreaming