CVE-2026-86543
published 2026-09-07CVE-2026-86543: knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh…
PriorityP273critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.86%
56.8th percentile
knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision a public tunnel and republish the API at a publicly accessible address.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| knowns-dev | knowns | < 0.30.0 | 0.30.0 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
knowns-dev knowns up to 0.29.x Management API /api/tunnel/start improper authentication
vuldb·2026-09-08·CVSS 9.8
CVE-2026-86543 [CRITICAL] knowns-dev knowns up to 0.29.x Management API /api/tunnel/start improper authentication
A vulnerability was found in knowns-dev knowns up to 0.29.x. It has been declared as critical. The impacted element is an unknown function of the file /api/tunnel/start of the component Management API. Such manipulation leads to improper authentication.
This vulnerability is uniquely identified as CVE-2026-86543. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
GHSA
knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations.
ghsa_unreviewed·2026-09-08
CVE-2026-86543 [CRITICAL] CWE-306 knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations.
knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision a public tunnel and republish the API at a publicly accessible address.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/knowns-dev/knowns/blob/v0.29.1/internal/cli/browser.go#L193-L200https://github.com/knowns-dev/knowns/blob/v0.29.1/internal/server/auth.go#L80-L86https://github.com/knowns-dev/knowns/blob/v0.29.1/internal/server/routes/tunnel.go#L26-L38https://github.com/knowns-dev/knowns/commit/878a02cb7cc14f0a592fdfda7a520af3cac500fbhttps://github.com/knowns-dev/knowns/releases/tag/v0.30.0https://github.com/knowns-dev/knowns/security/advisories/GHSA-fc85-99vc-9c75https://www.vulncheck.com/advisories/knowns-before-0.30.0-unauthenticated-management-api-exposure
2026-09-07
Published