{"id":"CVE-2026-92783","title":"Yeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, allowing users with read access to delete access control relationships","summary":"Yeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, allowing users with read access to delete access control relationships. Attackers can revoke the owner's grant and permanently lock legiti…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","cwe":["CWE-862"],"vendor":"yeti-platform","product":"yeti","affected":["yeti <= 2.11.0"],"published":"2026-09-16","updated":"2026-09-17","sourceUpdated":"2026-09-17T14:17:56.073","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92783","references":[{"url":"https://github.com/yeti-platform/yeti","label":"disclosure@vulncheck.com"},{"url":"https://github.com/yeti-platform/yeti/blob/2.5.1/core/web/apiv2/rbac.py#L110-L116","label":"disclosure@vulncheck.com"},{"url":"https://github.com/yeti-platform/yeti/blob/2.5.1/core/web/apiv2/rbac.py#L52-L53","label":"disclosure@vulncheck.com"},{"url":"https://github.com/yeti-platform/yeti/issues/1349","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/yeti-through-2.11.0-missing-authorization-on-rbac-relationship-deletion","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"total","timestamp":"2026-09-17T13:48:32.597739Z"},"ingestedAt":"2026-09-16T21:05:36.890Z","epss":0.00369,"epssPercentile":0.30742,"slug":"CVE-2026-92783","body":"## Overview\n\nYeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, allowing users with read access to delete access control relationships. Attackers can revoke the owner's grant and permanently lock legitimate owners out of objects.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":57,"depthScoreParts":{"impact":44.6,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":206105,"id":"CVE-2026-92783","ts":1789654823865,"field":"exploit_available","old":"false","new":"true"}]}