<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:kill_bill:kill_bill:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3akill_billkill_bill/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 03 Sep 2026 17:22:17 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3akill_billkill_bill/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Kill Bill Administrative Endpoint Permission Bypass</title><link>https://feed.craftedsignal.io/briefs/2026-09-kill-bill-permission-bypass/</link><pubDate>Thu, 03 Sep 2026 17:22:17 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-kill-bill-permission-bypass/</guid><description>Kill Bill versions 0.24.21 and earlier contain a security misconfiguration where authenticated users with minimal account:read privileges can perform unauthorized administrative actions.</description><content:encoded><![CDATA[<p>Kill Bill versions 0.24.21 and earlier suffer from a critical permission enforcement vulnerability (CVE-2026-85213) within the application's AdminResource endpoints. Security analysis confirms that the system fails to properly validate permissions for several sensitive administrative functions. Specifically, authenticated users who possess only minimal 'account:read' privileges can access restricted endpoints, including 'getQueueEntries', 'invalidatesCache', and 'putOutOfRotation'.</p>
<p>This vulnerability allows low-privileged users to perform actions that should be restricted to administrative roles. The impact ranges from information disclosure of internal system queues and server cache manipulation to a denial-of-service condition where a malicious actor can force the server out of rotation. This exposure poses a significant risk to the availability and integrity of Kill Bill deployments. Defenders should prioritize updating to the patched version of Kill Bill as soon as it becomes available to remediate this bypass of access control mechanisms.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows authenticated attackers with minimal privileges to perform unauthorized administrative actions, leading to internal information disclosure and service disruption via forced server rotation. This vulnerability affects all Kill Bill deployments running version 0.24.21 or earlier.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Monitor web application logs for unauthorized requests targeting the administrative API endpoints identified in this brief.</li>
<li>Patch Kill Bill to the latest version immediately once the fix for CVE-2026-85213 is released by the vendor.</li>
<li>Audit existing user permissions and restrict 'account:read' access to the minimum required level until the application is patched.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application-vulnerability</category><category>privilege-escalation</category><category>access-control</category></item></channel></rss>