Impact
The vulnerability allows any authenticated user to bypass role‑based access control on REST API endpoints, enabling them to invoke identity‑management functions. Attackers can create new administrative accounts or grant themselves such privileges without proper authorization. This results in a full escalation of privileges, potentially giving an attacker unrestricted access to all system data, configuration, and operational controls.
Affected Systems
The affected product is KnowStreaming, developed by didi. Versions up to and including 3.4.1 lack enforcement of role‑based restrictions on API endpoints. No other products or versions are explicitly listed as affected.
Risk and Exploitability
The CVSS score of 8.7 reflects a severe risk, while the EPSS score of less than 1% indicates that active exploitation is currently unlikely but possible. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely used in the wild. The likely attack vector is remote, requiring an authenticated session but no privileged role; once a user is authenticated, they can exploit the API to elevate to administrator status.
OpenCVE Enrichment