<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>KnowStreaming - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/knowstreaming/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 16 Sep 2026 21:56:10 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/knowstreaming/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>KnowStreaming RBAC Bypass Vulnerability</title><link>https://feed.craftedsignal.io/briefs/2026-09-knowstreaming-rbac-bypass/</link><pubDate>Wed, 16 Sep 2026 21:56:10 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-knowstreaming-rbac-bypass/</guid><description>KnowStreaming versions 3.4.1 and earlier contain an improper access control vulnerability in REST API endpoints that allows authenticated users to perform unauthorized privilege escalation.</description><content:encoded><![CDATA[<p>KnowStreaming versions through 3.4.1 contain a critical improper access control vulnerability, tracked as CVE-2026-92780. The software fails to enforce role-based access control (RBAC) on its REST API endpoints. This flaw allows any authenticated user to interact with sensitive administrative functionality that should be restricted to privileged accounts. Specifically, attackers can target identity-management endpoints to create new administrator accounts or modify existing user permissions to grant themselves administrative privileges. This vulnerability poses a significant risk to the integrity and confidentiality of the KnowStreaming environment, as it effectively nullifies the application's authorization model. Defenders should prioritize patching, as this vulnerability allows a standard user to gain full administrative control over the application.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability enables an attacker to perform full privilege escalation within the KnowStreaming application. By creating rogue administrator accounts or elevating existing low-privileged accounts, an attacker can gain persistent access, exfiltrate sensitive data, or manipulate streaming configurations. This impacts any organization using KnowStreaming for identity management and content control, potentially leading to a complete compromise of the application instance.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Patch KnowStreaming to the latest version immediately, as version 3.4.1 and earlier are confirmed vulnerable to CVE-2026-92780.</li>
<li>Review audit logs for unauthorized user account creation or modification events occurring via the REST API.</li>
<li>Restrict access to the KnowStreaming REST API endpoints to only known, trusted management IP addresses at the network or web proxy layer.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>