๐Ÿ” CVE Alert

CVE-2026-86543

CRITICAL 9.8

knowns before 0.30.0 Unauthenticated Management API Exposure

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision a public tunnel and republish the API at a publicly accessible address.

CWE CWE-306
Vendor knowns-dev
Product knowns
Published Sep 7, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for knowns-dev knowns

Be the first to know when new critical vulnerabilities affecting knowns-dev knowns are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

knowns-dev / knowns
0 < 0.30.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/knowns-dev/knowns/security/advisories/GHSA-fc85-99vc-9c75 github.com: https://github.com/knowns-dev/knowns/blob/v0.29.1/internal/server/auth.go#L80-L86 github.com: https://github.com/knowns-dev/knowns/blob/v0.29.1/internal/cli/browser.go#L193-L200 github.com: https://github.com/knowns-dev/knowns/blob/v0.29.1/internal/server/routes/tunnel.go#L26-L38 github.com: https://github.com/knowns-dev/knowns/commit/878a02cb7cc14f0a592fdfda7a520af3cac500fb github.com: https://github.com/knowns-dev/knowns/releases/tag/v0.30.0 vulncheck.com: https://www.vulncheck.com/advisories/knowns-before-0.30.0-unauthenticated-management-api-exposure

Credits

๐Ÿ” Tong Hoang Gia (uziii2208) ๐Ÿ” Nguyen Huy Hoang (hoanggxyuuki)