CVE-2026-85213
Kill Bill through 0.24.21 fails to enforce permission annotations on several AdminResource endpoints including getQueueEntries, invalidatesCache, and putOutOfRotation. Authenticated users with minimal account:read permissions can read internal queues, flush server caches, and disable the server by putting the host out of rotation.
- Published Sep 3, 2026
- CVSS 7.2 high
- 0.4% chance of exploitation in the next 30 days (EPSS)