{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/yeti/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:yeti:yeti:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-92783"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Yeti (\u003c= 2.11.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Yeti"],"content_html":"\u003cp\u003eYeti versions up to and including 2.11.0 contain a critical authorization vulnerability (CVE-2026-92783) within the RBAC API management subsystem. The vulnerability resides in the DELETE /api/v2/rbac/{id} endpoint, which lacks sufficient server-side permission validation. This flaw allows an authenticated attacker possessing only read-only access to successfully invoke the deletion of access control entries for objects they do not own. By exploiting this oversight, an attacker can revoke administrative grants or ownership associations, resulting in a persistent state where legitimate owners are permanently locked out of their objects and denied administrative control. This represents a significant integrity and availability risk for environments utilizing Yeti for access management.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in unauthorized modification of security policies and permanent denial of service for administrative object management. In multi-tenant or collaborative environments, an attacker with low-privileged read access can effectively neutralize security controls, prevent legitimate administrators from accessing critical data, and disrupt organizational workflows.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate update of all Yeti instances to a patched version beyond 2.11.0. If immediate patching is not feasible, restrict access to the /api/v2/rbac/ endpoint using a web application firewall or reverse proxy to block DELETE methods from unauthorized accounts.\u003c/p\u003e\n","date_modified":"2026-09-16T21:56:27Z","date_published":"2026-09-16T21:56:27Z","id":"https://feed.craftedsignal.io/briefs/2026-09-yeti-rbac-bypass/","summary":"Yeti versions 2.11.0 and earlier contain an authorization vulnerability in the DELETE /api/v2/rbac/{id} endpoint that allows unauthorized users to delete access control relationships, causing permanent lockout of legitimate object owners.","title":"Authorization Bypass in Yeti RBAC API","url":"https://feed.craftedsignal.io/briefs/2026-09-yeti-rbac-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Yeti","version":"https://jsonfeed.org/version/1.1"}