{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3akill_billkill_bill/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:kill_bill:kill_bill:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.6,"id":"CVE-2026-85213"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Kill Bill (\u003c= 0.24.21)"],"_cs_severities":["high"],"_cs_tags":["web-application-vulnerability","privilege-escalation","access-control"],"_cs_type":"advisory","_cs_vendors":["Kill Bill"],"content_html":"\u003cp\u003eKill Bill versions 0.24.21 and earlier suffer from a critical permission enforcement vulnerability (CVE-2026-85213) within the application's AdminResource endpoints. Security analysis confirms that the system fails to properly validate permissions for several sensitive administrative functions. Specifically, authenticated users who possess only minimal 'account:read' privileges can access restricted endpoints, including 'getQueueEntries', 'invalidatesCache', and 'putOutOfRotation'.\u003c/p\u003e\n\u003cp\u003eThis vulnerability allows low-privileged users to perform actions that should be restricted to administrative roles. The impact ranges from information disclosure of internal system queues and server cache manipulation to a denial-of-service condition where a malicious actor can force the server out of rotation. This exposure poses a significant risk to the availability and integrity of Kill Bill deployments. Defenders should prioritize updating to the patched version of Kill Bill as soon as it becomes available to remediate this bypass of access control mechanisms.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated attackers with minimal privileges to perform unauthorized administrative actions, leading to internal information disclosure and service disruption via forced server rotation. This vulnerability affects all Kill Bill deployments running version 0.24.21 or earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor web application logs for unauthorized requests targeting the administrative API endpoints identified in this brief.\u003c/li\u003e\n\u003cli\u003ePatch Kill Bill to the latest version immediately once the fix for CVE-2026-85213 is released by the vendor.\u003c/li\u003e\n\u003cli\u003eAudit existing user permissions and restrict 'account:read' access to the minimum required level until the application is patched.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T17:22:17Z","date_published":"2026-09-03T17:22:17Z","id":"https://feed.craftedsignal.io/briefs/2026-09-kill-bill-permission-bypass/","summary":"Kill Bill versions 0.24.21 and earlier contain a security misconfiguration where authenticated users with minimal account:read privileges can perform unauthorized administrative actions.","title":"Kill Bill Administrative Endpoint Permission Bypass","url":"https://feed.craftedsignal.io/briefs/2026-09-kill-bill-permission-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:kill_bill:kill_bill:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}