Impact
Kiteworks Core before version 9.5.0 suffers from improper privilege management (CWE‑269). The flaw allows an authenticated administrative user that normally has limited, non‑Sysadmin role‑management permissions to grant full system‑administrator privileges to another user, bypassing the intended restrictions. As a result, a non‑privileged admin could elevate another account to full administrative control, potentially compromising confidentiality, integrity, and availability of the entire system.
Affected Systems
The affected product is Kiteworks Core, specifically all releases older than version 9.5.0. Users running Kiteworks Core 9.4.x or earlier must verify their deployment and apply the appropriate update to prevent unauthorized role escalation.
Risk and Exploitability
The CVSS score of 7.2 denotes a high severity vulnerability. Although the EPSS score is not available, the lack of inclusion in the CISA KEV catalog suggests that no widespread exploitation has been observed yet. Nonetheless, the attack requires only an authenticated administrative session with limited role‑management rights, which is a relatively common privilege level in many deployments. If such a user abuses the flaw, they can grant themselves or others full system‑administrator rights, enabling comprehensive control over the platform. Therefore, the risk to organizations using vulnerable Kiteworks Core installations is significant, necessitating timely remediation.
OpenCVE Enrichment