CVE-2026-86543
knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password require
CVSS
9.8
Crítico
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 7 sept 2026 · Última mod.: 7 sept 2026 · CWE-306
Sin historial EPSS suficiente todavía.
knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision a public tunnel and republish the API at a publicly accessible address.
- github.comhttps://github.com/knowns-dev/knowns/blob/v0.29.1/internal/cli/browser.go#L193-L200
- github.comhttps://github.com/knowns-dev/knowns/blob/v0.29.1/internal/server/auth.go#L80-L86
- github.comhttps://github.com/knowns-dev/knowns/blob/v0.29.1/internal/server/routes/tunnel.go#L26-L38
- github.comhttps://github.com/knowns-dev/knowns/commit/878a02cb7cc14f0a592fdfda7a520af3cac500fb
- github.comhttps://github.com/knowns-dev/knowns/releases/tag/v0.30.0
- github.comhttps://github.com/knowns-dev/knowns/security/advisories/GHSA-fc85-99vc-9c75
- www.vulncheck.comhttps://www.vulncheck.com/advisories/knowns-before-0.30.0-unauthenticated-management-api-exposure
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-865065.9 MED—
———In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling data13hCVE-2026-865028.4 ALT—
———In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts13hCVE-2026-864863.7 BAJ—
———In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank13hCVE-2026-864809.8 CRÍ—
———In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges13hCVE-2026-796458.2 ALT—
———Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.15hCVE-2026-784807.5 ALT—
———Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.15h