Description
KnowStreaming through 3.4.1 fails to enforce role-based access control on REST API endpoints, allowing any authenticated user to access protected functionality. Attackers can call identity-management endpoints to create administrator accounts or grant themselves administrative privileges without proper authorization.
Published: 2026-09-16
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via Unrestricted API Access
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows any authenticated user to bypass role‑based access control on REST API endpoints, enabling them to invoke identity‑management functions. Attackers can create new administrative accounts or grant themselves such privileges without proper authorization. This results in a full escalation of privileges, potentially giving an attacker unrestricted access to all system data, configuration, and operational controls.

Affected Systems

The affected product is KnowStreaming, developed by didi. Versions up to and including 3.4.1 lack enforcement of role‑based restrictions on API endpoints. No other products or versions are explicitly listed as affected.

Risk and Exploitability

The CVSS score of 8.7 reflects a severe risk, while the EPSS score of less than 1% indicates that active exploitation is currently unlikely but possible. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely used in the wild. The likely attack vector is remote, requiring an authenticated session but no privileged role; once a user is authenticated, they can exploit the API to elevate to administrator status.

Generated by OpenCVE AI on September 17, 2026 at 22:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade KnowStreaming to a version newer than 3.4.1, where the role-based access control is enforced on all REST endpoints.
  • If an immediate upgrade is not possible, limit API exposure by restricting access to trusted IP ranges or applying network segmentation so that only internal or authenticated systems can call the identity‑management endpoints.
  • Modify or replace the current PermissionInterceptor implementation to enforce role validation on all protected endpoints, ensuring that only users with administrative roles can invoke identity‑management functions. If custom code is used, implement an explicit filter that rejects requests lacking the required role before reaching the endpoint logic.

Generated by OpenCVE AI on September 17, 2026 at 22:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Didi
Didi knowstreaming
Vendors & Products Didi
Didi knowstreaming

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description KnowStreaming through 3.4.1 fails to enforce role-based access control on REST API endpoints, allowing any authenticated user to access protected functionality. Attackers can call identity-management endpoints to create administrator accounts or grant themselves administrative privileges without proper authorization.
Title KnowStreaming through 3.4.1 Missing Authorization on the REST API
First Time appeared Knowstreaming Project
Knowstreaming Project knowstreaming
Weaknesses CWE-862
CPEs cpe:2.3:a:knowstreaming_project:knowstreaming:*:*:*:*:*:*:*:*
Vendors & Products Knowstreaming Project
Knowstreaming Project knowstreaming
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Didi Knowstreaming
Knowstreaming Project Knowstreaming
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T15:03:02.465Z

Reserved: 2026-09-16T19:22:53.441Z

Link: CVE-2026-92780

cve-icon Vulnrichment

Updated: 2026-09-17T15:02:57.282Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:26.987

Modified: 2026-09-24T20:48:01.433

Link: CVE-2026-92780

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:03:23Z

Weaknesses