CVE-2026-92783
EUVD-2026-8104616.09.2026, 21:17
Yeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, allowing users with read access to delete access control relationships. Attackers can revoke the owner's grant and permanently lock legitimate owners out of objects.EnginsightAwaiting analysis
This vulnerability is currently awaiting analysis.
Common Weakness Enumeration
References