CVE-2026-92780: KnowStreaming through 3.4.1 Missing Authorization on the REST API
Published Sep 16, 2026
·Updated
KnowStreaming through 3.4.1 fails to enforce role-based access control on REST API endpoints, allowing any authenticated user to access protected functionality. Attackers can call identity-management endpoints to create administrator accounts or grant themselves administrative privileges without proper authorization.
Affected Software
1 affected component
KnowStreaming KnowStreaming<=3.4.1
Event History
Sep 16, 2026
CVE Published
via MITRE·08:32 PM
Data Sourced
via MITRE·08:32 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker needs to be authenticated as any KnowStreaming user. No administrative role or user interaction is required.
2
What could an attacker do after exploiting the affected API endpoints?
An authenticated low-privileged user can access protected REST API functionality, including identity-management endpoints. They may create administrator accounts or grant themselves administrative privileges.
3
Are deployments running version 3.4.1 affected?
Yes. The affected range is KnowStreaming through version 3.4.1.