Access Control Vulnerability in KnowStreaming by Didi
CVE-2026-92780
8.7HIGH
What is CVE-2026-92780?
The KnowStreaming platform, up to version 3.4.1, contains a significant security flaw that fails to implement proper role-based access control on its REST API endpoints. This oversight allows any authenticated user to exploit the system by accessing sensitive functionality without appropriate permissions. Attackers can invoke identity-management endpoints, which could enable them to create administrator accounts or elevate their privileges unlawfully, leading to potential unauthorized access and manipulation of the application’s critical features.
Affected Version(s)
KnowStreaming 0 <= 3.4.1
