{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-86775/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:knowns_project:knowns:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-86543"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["knowns (\u003c 0.30.0)","knowns (\u003c= 0.29.1)"],"_cs_severities":["critical"],"_cs_tags":["web-vulnerability","path-traversal","npm","cve-2026-86775"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe knowns application, in versions prior to 0.30.0, contains a critical authentication bypass vulnerability in its management API component. By default, this API is configured to listen on all network interfaces without requiring any form of authentication or credentials upon fresh installation. This misconfiguration allows unauthenticated remote attackers to interact with sensitive administrative endpoints. Specifically, an attacker can access the /api/tunnel/start endpoint to provision a new, unauthorized public tunnel. This action can be used to republish the internal management API to a publicly accessible address, effectively bypassing internal network boundaries and enabling further unauthorized access or control over the host system. Given the default behavior of exposing the API on all interfaces, this threat is highly accessible to any actor capable of reaching the service over the network.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the unauthorized creation of external tunnels, potentially exposing internal-only services or management interfaces to the public internet. This can lead to unauthorized configuration changes, complete takeover of the knowns application instance, and lateral movement within the network. This vulnerability carries a CVSS v3.1 base score of 9.8.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the knowns application to version 0.30.0 or later immediately to enforce authentication requirements on the management API.\u003c/li\u003e\n\u003cli\u003eImplement network access control lists (ACLs) to restrict access to the knowns management API port to trusted internal management subnets only.\u003c/li\u003e\n\u003cli\u003eReview network logs for unexpected inbound HTTP requests to the /api/tunnel/start endpoint, which is a strong indicator of unauthorized tunnel provisioning.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-09T14:59:50Z","date_published":"2026-09-08T01:37:49Z","id":"https://feed.craftedsignal.io/briefs/2026-09-knowns-auth-bypass/","summary":"The knowns application before version 0.30.0 exposes an unauthenticated management API on all network interfaces, allowing attackers to provision unauthorized tunnels via the /api/tunnel/start endpoint.","title":"Authentication Bypass in knowns Management API","url":"https://feed.craftedsignal.io/briefs/2026-09-knowns-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-86775","version":"https://jsonfeed.org/version/1.1"}