HIGH
CVE-2026-92783
CVSS
8.1
Description
Yeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, allowing users with read access to delete access control relationships. Attackers can revoke the owner's grant and permanently lock legitimate owners out of objects.
Weakness (CWE)
CWE-862
Missing Authorization
EPSS Score
0.37%
Probability of exploitation in next 30 days
30.7th percentile
References
https://github.com/yeti-platform/yeti
https://github.com/yeti-platform/yeti/blob/2.5.1/core/web/apiv2/rbac.py#L110-L116
https://github.com/yeti-platform/yeti/blob/2.5.1/core/web/apiv2/rbac.py#L52-L53
https://github.com/yeti-platform/yeti/issues/1349
https://www.vulncheck.com/advisories/yeti-through-2.11.0-missing-authorization-on-rbac-relationship-deletion
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.