CVE-2026-86543
knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password require
CVSS
9.8
Critical
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 7, 2026 · Last modified: Sep 7, 2026 · CWE-306
Not enough EPSS history yet.
knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision a public tunnel and republish the API at a publicly accessible address.
- github.comhttps://github.com/knowns-dev/knowns/blob/v0.29.1/internal/cli/browser.go#L193-L200
- github.comhttps://github.com/knowns-dev/knowns/blob/v0.29.1/internal/server/auth.go#L80-L86
- github.comhttps://github.com/knowns-dev/knowns/blob/v0.29.1/internal/server/routes/tunnel.go#L26-L38
- github.comhttps://github.com/knowns-dev/knowns/commit/878a02cb7cc14f0a592fdfda7a520af3cac500fb
- github.comhttps://github.com/knowns-dev/knowns/releases/tag/v0.30.0
- github.comhttps://github.com/knowns-dev/knowns/security/advisories/GHSA-fc85-99vc-9c75
- www.vulncheck.comhttps://www.vulncheck.com/advisories/knowns-before-0.30.0-unauthenticated-management-api-exposure
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-865065.9 MED—
———In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling data12hCVE-2026-865028.4 HIG—
———In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts12hCVE-2026-864863.7 LOW—
———In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank12hCVE-2026-864809.8 CRI—
———In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges12hCVE-2026-796458.2 HIG—
———Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.14hCVE-2026-784807.5 HIG—
———Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.14h