Description
knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions. Attackers can invoke project.set to repoint the server at another project directory and obtain write access capabilities.
Published: 2026-09-10
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass with unintended write privileges
Action: Immediate Patch
AI Analysis

Impact

This vulnerability allows an attacker with only read‑only agent session privileges to bypass the permission guard for the project.set action. Because the action is exempt from checks, the attacker can redirect the server to a different project directory and gain write access, effectively contaminating or overwriting project data.

Affected Systems

The affected product is knowns from the vendor knowns-dev. All releases up to and including version 0.33.0 contain the flaw; versions after 0.33.0 are presumed patched unless otherwise noted.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity vulnerability with a high impact on confidentiality, integrity, and availability. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a remote API or service call to project.set performed by an attacker who can establish a read‑only agent session. The vulnerability is exploitable without additional prerequisites beyond possessing the ability to invoke project.set, making it a significant risk for environments with exposed agent interfaces.

Generated by OpenCVE AI on September 10, 2026 at 17:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest knowns update that removes the unconditional exemption for project.set; no patch is available for versions older than 0.33.1 and those should be upgraded if possible.
  • Configure the permission model to explicitly deny project.set for read‑only sessions, ensuring that only users with explicit write authorization can execute this action.
  • Audit and monitor agent sessions for unexpected project.set calls and revoke any sessions that attempt to modify project directories without proper authorization.

Generated by OpenCVE AI on September 10, 2026 at 17:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Knowns-dev
Knowns-dev knowns
Vendors & Products Knowns-dev
Knowns-dev knowns

Thu, 10 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions. Attackers can invoke project.set to repoint the server at another project directory and obtain write access capabilities.
Title knowns through 0.33.0 Authorization Bypass via project.set Bootstrap Exemption
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Knowns-dev Knowns
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T14:40:10.438Z

Reserved: 2026-09-10T14:55:29.628Z

Link: CVE-2026-88939

cve-icon Vulnrichment

Updated: 2026-09-15T14:39:20.854Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T16:18:12.577

Modified: 2026-09-15T15:17:26.583

Link: CVE-2026-88939

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T09:45:06Z

Weaknesses