GHSA-h7r9-wrf2-gr7gHighCVSS 8.8

KnowStreaming through 3.4.1 fails to enforce role-based access control on REST API endpoints,...

Published
September 16, 2026
Last Modified
September 16, 2026

🔗 CVE IDs covered (1)

📋 Description

KnowStreaming through 3.4.1 fails to enforce role-based access control on REST API endpoints, allowing any authenticated user to access protected functionality. Attackers can call identity-management endpoints to create administrator accounts or grant themselves administrative privileges without proper authorization.

🔗 References (6)