{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/knowstreaming--3.4.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:knowstreaming:knowstreaming:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-92780"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["KnowStreaming (\u003c= 3.4.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["KnowStreaming"],"content_html":"\u003cp\u003eKnowStreaming versions through 3.4.1 contain a critical improper access control vulnerability, tracked as CVE-2026-92780. The software fails to enforce role-based access control (RBAC) on its REST API endpoints. This flaw allows any authenticated user to interact with sensitive administrative functionality that should be restricted to privileged accounts. Specifically, attackers can target identity-management endpoints to create new administrator accounts or modify existing user permissions to grant themselves administrative privileges. This vulnerability poses a significant risk to the integrity and confidentiality of the KnowStreaming environment, as it effectively nullifies the application's authorization model. Defenders should prioritize patching, as this vulnerability allows a standard user to gain full administrative control over the application.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability enables an attacker to perform full privilege escalation within the KnowStreaming application. By creating rogue administrator accounts or elevating existing low-privileged accounts, an attacker can gain persistent access, exfiltrate sensitive data, or manipulate streaming configurations. This impacts any organization using KnowStreaming for identity management and content control, potentially leading to a complete compromise of the application instance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch KnowStreaming to the latest version immediately, as version 3.4.1 and earlier are confirmed vulnerable to CVE-2026-92780.\u003c/li\u003e\n\u003cli\u003eReview audit logs for unauthorized user account creation or modification events occurring via the REST API.\u003c/li\u003e\n\u003cli\u003eRestrict access to the KnowStreaming REST API endpoints to only known, trusted management IP addresses at the network or web proxy layer.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T21:56:10Z","date_published":"2026-09-16T21:56:10Z","id":"https://feed.craftedsignal.io/briefs/2026-09-knowstreaming-rbac-bypass/","summary":"KnowStreaming versions 3.4.1 and earlier contain an improper access control vulnerability in REST API endpoints that allows authenticated users to perform unauthorized privilege escalation.","title":"KnowStreaming RBAC Bypass Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-09-knowstreaming-rbac-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - KnowStreaming (\u003c= 3.4.1)","version":"https://jsonfeed.org/version/1.1"}