Authorization Bypass in KnownS Product by KnownS Dev
CVE-2026-86544

7.2HIGH

Key Information:

Vendor

Knowns-dev

Status
Vendor
CVE Published:
7 September 2026

What is CVE-2026-86544?

The vulnerability in KnownS allows attackers with limited read access to exploit the misclassification of mutating code actions as read-only. This flaw enables unauthorized modifications to permission configurations, facilitating potential privilege escalation during subsequent operations. It affects known versions prior to 0.30.0, highlighting the importance of updating to mitigate associated risks.

Affected Version(s)

knowns 0 < 0.30.0

knowns 0.30.0

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tong Hoang Gia
Nguyen Huy Hoang
.