Description
Kiteworks Core before version 9.5.0 is vulnerable to Improper Privilege Management and does not correctly enforce restrictions on role assignment, which could allow an authenticated administrative user with limited, non-Sysadmin role-management permissions to elevate another user to full system-administrator privileges beyond those the administrative user was authorized to grant.
Published: 2026-09-30
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Patch
AI Analysis

Impact

Kiteworks Core before version 9.5.0 suffers from improper privilege management (CWE‑269). The flaw allows an authenticated administrative user that normally has limited, non‑Sysadmin role‑management permissions to grant full system‑administrator privileges to another user, bypassing the intended restrictions. As a result, a non‑privileged admin could elevate another account to full administrative control, potentially compromising confidentiality, integrity, and availability of the entire system.

Affected Systems

The affected product is Kiteworks Core, specifically all releases older than version 9.5.0. Users running Kiteworks Core 9.4.x or earlier must verify their deployment and apply the appropriate update to prevent unauthorized role escalation.

Risk and Exploitability

The CVSS score of 7.2 denotes a high severity vulnerability. Although the EPSS score is not available, the lack of inclusion in the CISA KEV catalog suggests that no widespread exploitation has been observed yet. Nonetheless, the attack requires only an authenticated administrative session with limited role‑management rights, which is a relatively common privilege level in many deployments. If such a user abuses the flaw, they can grant themselves or others full system‑administrator rights, enabling comprehensive control over the platform. Therefore, the risk to organizations using vulnerable Kiteworks Core installations is significant, necessitating timely remediation.

Generated by OpenCVE AI on September 30, 2026 at 22:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Kiteworks Core to version 9.5.0 or newer, which contains the privilege management fix.
  • If an update is not immediately possible, tightly restrict the role‑management permissions granted to administrative users, ensuring that only users with explicit approval can assign high‑privilege roles.
  • Enable audit logging for all role assignment changes and conduct regular reviews of role configurations to detect any unauthorized privilege escalations.

Generated by OpenCVE AI on September 30, 2026 at 22:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Kiteworks
Kiteworks core
Vendors & Products Kiteworks
Kiteworks core

Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description Kiteworks Core before version 9.5.0 is vulnerable to Improper Privilege Management and does not correctly enforce restrictions on role assignment, which could allow an authenticated administrative user with limited, non-Sysadmin role-management permissions to elevate another user to full system-administrator privileges beyond those the administrative user was authorized to grant.
Title Kiteworks Core improper privilege management
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-09-30T20:06:49.237Z

Reserved: 2026-09-28T17:39:13.561Z

Link: CVE-2026-102093

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T21:16:55.870

Modified: 2026-10-01T02:17:43.350

Link: CVE-2026-102093

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T05:00:12Z

Weaknesses
  • CWE-269

    Improper Privilege Management