CVE-2026-102129
7.2
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Summary
A user-provisioning interface in Kiteworks Core did not verify that the requesting administrator was entitled to grant the role being assigned. An administrator whose delegated permissions covered role changes alone could therefore raise an account to full system-administrator privileges.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Kiteworks | Core | 0 < 9.5.1 | affected |
| Kiteworks | Core | 9.5.1 | unaffected |
Weaknesses
- CWE-266: CWE-266 Incorrect Privilege Assignment
References
- https://github.com/kiteworks/security-advisories/security/advisories/GHSA-4gcf-w86v-34rp
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.