Kill Bill versions through 0.24.21 contain a missing authorization vulnerability affecting several AdminResource endpoints. The affected endpoints include getQueueEntries, invalidatesCache, and putOutOfRotation, which fail to enforce their permission annotations. Authenticated users possessing only minimal account:read permissions can exploit this flaw to read internal queues, flush server caches, and disable the server by putting the host out of rotation. This represents a significant privilege escalation risk, allowing low-privileged users to perform administrative actions. The vulnerability is tracked as CVE-2026-85213 and has been reported via the Kill Bill GitHub issue tracker and VulnCheck advisories.