CVE-2026-92780
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
16/09/2026
Last modified:
24/09/2026
Description
KnowStreaming through 3.4.1 fails to enforce role-based access control on REST API endpoints, allowing any authenticated user to access protected functionality. Attackers can call identity-management endpoints to create administrator accounts or grant themselves administrative privileges without proper authorization.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
8.80
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/didi/KnowStreaming
- https://github.com/didi/KnowStreaming/blob/v3.4.0/km-rest/src/main/java/com/xiaojukeji/know/streaming/km/rest/interceptor/PermissionInterceptor.java#L46-L74
- https://github.com/didi/KnowStreaming/issues/1263
- https://www.vulncheck.com/advisories/knowstreaming-through-3.4.1-missing-authorization-on-the-rest-api
- https://github.com/didi/KnowStreaming/issues/1263


