Product
Yeti versions 2.11.0 and earlier contain an authorization vulnerability in the DELETE /api/v2/rbac/{id} endpoint that allows unauthorized users to delete access control relationships, causing permanent lockout of legitimate object owners.