CVE-2026-92780
KnowStreaming through 3.4.1 Missing Authorization on the REST API
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
KnowStreaming through 3.4.1 fails to enforce role-based access control on REST API endpoints, allowing any authenticated user to access protected functionality. Attackers can call identity-management endpoints to create administrator accounts or grant themselves administrative privileges without proper authorization.
| CWE | CWE-862 |
| Vendor | didi |
| Product | knowstreaming |
| Published | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for didi knowstreaming
Be the first to know when new high vulnerabilities affecting didi knowstreaming are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
didi / KnowStreaming
0 โค 3.4.1
References
github.com: https://github.com/didi/KnowStreaming/issues/1263 github.com: https://github.com/didi/KnowStreaming github.com: https://github.com/didi/KnowStreaming/blob/v3.4.0/km-rest/src/main/java/com/xiaojukeji/know/streaming/km/rest/interceptor/PermissionInterceptor.java#L46-L74 vulncheck.com: https://www.vulncheck.com/advisories/knowstreaming-through-3.4.1-missing-authorization-on-the-rest-api
Credits
George Chen