KnowStreaming RBAC Bypass Vulnerability
KnowStreaming versions 3.4.1 and earlier contain an improper access control vulnerability in REST API endpoints that allows authenticated users to perform unauthorized privilege escalation.
CVE search metadata
CVE search record: CVE-2026-92780. Severity: high. CVSS: 8.8. KEV: no. Product: KnowStreaming (<= 3.4.1). Brief: KnowStreaming RBAC Bypass Vulnerability. Brief link: https://feed.craftedsignal.io/briefs/2026-09-knowstreaming-rbac-bypass/
KnowStreaming versions through 3.4.1 contain a critical improper access control vulnerability, tracked as CVE-2026-92780. The software fails to enforce role-based access control (RBAC) on its REST API endpoints. This flaw allows any authenticated user to interact with sensitive administrative functionality that should be restricted to privileged accounts. Specifically, attackers can target identity-management endpoints to create new administrator accounts or modify existing user permissions to grant themselves administrative privileges. This vulnerability poses a significant risk to the integrity and confidentiality of the KnowStreaming environment, as it effectively nullifies the application's authorization model. Defenders should prioritize patching, as this vulnerability allows a standard user to gain full administrative control over the application.
Impact
Successful exploitation of this vulnerability enables an attacker to perform full privilege escalation within the KnowStreaming application. By creating rogue administrator accounts or elevating existing low-privileged accounts, an attacker can gain persistent access, exfiltrate sensitive data, or manipulate streaming configurations. This impacts any organization using KnowStreaming for identity management and content control, potentially leading to a complete compromise of the application instance.
Recommendation
- Patch KnowStreaming to the latest version immediately, as version 3.4.1 and earlier are confirmed vulnerable to CVE-2026-92780.
- Review audit logs for unauthorized user account creation or modification events occurring via the REST API.
- Restrict access to the KnowStreaming REST API endpoints to only known, trusted management IP addresses at the network or web proxy layer.
Immediate actions
Patch KnowStreaming to a version beyond 3.4.1
Mitigations
Restrict network access to KnowStreaming API endpoints
CVE-2026-92780
Detection coverage 1
Detect CVE-2026-92780 Exploitation - Unauthorized Account Creation
highDetects unauthorized attempts to access identity management API endpoints potentially related to CVE-2026-92780 exploitation
Detection queries are available on the platform. Get full rules →