Skip to content
Threat Feed
high advisory

KnowStreaming RBAC Bypass Vulnerability

KnowStreaming versions 3.4.1 and earlier contain an improper access control vulnerability in REST API endpoints that allows authenticated users to perform unauthorized privilege escalation.

CVE search metadata

CVE search record: CVE-2026-92780. Severity: high. CVSS: 8.8. KEV: no. Product: KnowStreaming (<= 3.4.1). Brief: KnowStreaming RBAC Bypass Vulnerability. Brief link: https://feed.craftedsignal.io/briefs/2026-09-knowstreaming-rbac-bypass/

KnowStreaming versions through 3.4.1 contain a critical improper access control vulnerability, tracked as CVE-2026-92780. The software fails to enforce role-based access control (RBAC) on its REST API endpoints. This flaw allows any authenticated user to interact with sensitive administrative functionality that should be restricted to privileged accounts. Specifically, attackers can target identity-management endpoints to create new administrator accounts or modify existing user permissions to grant themselves administrative privileges. This vulnerability poses a significant risk to the integrity and confidentiality of the KnowStreaming environment, as it effectively nullifies the application's authorization model. Defenders should prioritize patching, as this vulnerability allows a standard user to gain full administrative control over the application.

Impact

Successful exploitation of this vulnerability enables an attacker to perform full privilege escalation within the KnowStreaming application. By creating rogue administrator accounts or elevating existing low-privileged accounts, an attacker can gain persistent access, exfiltrate sensitive data, or manipulate streaming configurations. This impacts any organization using KnowStreaming for identity management and content control, potentially leading to a complete compromise of the application instance.

Recommendation

  • Patch KnowStreaming to the latest version immediately, as version 3.4.1 and earlier are confirmed vulnerable to CVE-2026-92780.
  • Review audit logs for unauthorized user account creation or modification events occurring via the REST API.
  • Restrict access to the KnowStreaming REST API endpoints to only known, trusted management IP addresses at the network or web proxy layer.

Immediate actions

Patch KnowStreaming to a version beyond 3.4.1

IT Operations 24h

Mitigations

Restrict network access to KnowStreaming API endpoints

immediate IT Operations

CVE-2026-92780

Detection coverage 1

Detect CVE-2026-92780 Exploitation - Unauthorized Account Creation

high

Detects unauthorized attempts to access identity management API endpoints potentially related to CVE-2026-92780 exploitation

sigma tactics: privilege_escalation techniques: T1068 sources: webserver

Detection queries are available on the platform. Get full rules →