CVE-2026-92783 UNKNOWN

CVE-2026-92783

Published: 2026-09-16

Description

Yeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, allowing users with read access to delete access control relationships. Attackers can revoke the owner's grant and permanently lock legitimate owners out of objects.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…