Access Control Vulnerability in KnowStreaming by Didi
CVE-2026-92780

8.7HIGH

Key Information:

Vendor

Didi

Vendor
CVE Published:
16 September 2026

What is CVE-2026-92780?

The KnowStreaming platform, up to version 3.4.1, contains a significant security flaw that fails to implement proper role-based access control on its REST API endpoints. This oversight allows any authenticated user to exploit the system by accessing sensitive functionality without appropriate permissions. Attackers can invoke identity-management endpoints, which could enable them to create administrator accounts or elevate their privileges unlawfully, leading to potential unauthorized access and manipulation of the application’s critical features.

Affected Version(s)

KnowStreaming 0 <= 3.4.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.