Description
Kiteworks did not enforce the maximum permitted value for a configurable security-policy setting. An authenticated administrator could set this value outside its intended range so that the associated control never activated, while the control continued to appear enabled in the administrative interface and audit log, allowing it to be silently rendered ineffective.
Published: 2026-09-30
Score: 4.9 Medium
EPSS: n/a
KEV: No
Impact: Silent policy bypass via configuration misuse
Action: Assess Impact
AI Analysis

Impact

The vulnerability originates from a failure to enforce the maximum permitted value for a configurable security-policy setting. An authenticated administrator can set this value beyond its intended limits, causing the associated enforcement control to remain inactive while the user interface and audit logs indicate that the control is active. This silent disabling allows subsequent privileged actions to bypass the intended security check without detection.

Affected Systems

All deployments of Kiteworks Core are potentially affected because the flaw exists in the core configuration handling. No specific version numbers are disclosed in the advisory, so administrators should treat every installation as a candidate for review until a patched version becomes available.

Risk and Exploitability

The CVSS score of 4.9 signifies moderate impact, and the exploitation vector is limited to administrators with valid credentials, as the attacker must first change a configuration value. EPSS is not available and the vulnerability is not listed in CISA KEV, indicating that widespread exploitation has not been observed. However, the flaw could be leveraged by a malicious or compromised administrator to silently disable an important control, thus potentially compromising data integrity or confidentiality.

Generated by OpenCVE AI on September 30, 2026 at 22:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any vendor-released patch or update that limits the configurable quantity to its intended maximum.
  • Reset the affected configuration value to the default or a safe maximum and verify that the control activates correctly.
  • Review all security-policy related configuration parameters and apply strict validation checks.
  • Audit and monitor administrative changes to configuration values, especially those controlling enforcement rules, to detect unauthorized alterations.
  • Disable or isolate the affected feature until a proper fix is deployed.

Generated by OpenCVE AI on September 30, 2026 at 22:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description Kiteworks did not enforce the maximum permitted value for a configurable security-policy setting. An authenticated administrator could set this value outside its intended range so that the associated control never activated, while the control continued to appear enabled in the administrative interface and audit log, allowing it to be silently rendered ineffective.
Title Kiteworks Core Improper Validation of Specified Quantity in Input
Weaknesses CWE-1284
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-09-30T20:21:15.283Z

Reserved: 2026-09-28T17:39:13.562Z

Link: CVE-2026-102111

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T21:16:58.137

Modified: 2026-09-30T21:16:58.137

Link: CVE-2026-102111

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T22:30:07Z

Weaknesses
  • CWE-1284

    Improper Validation of Specified Quantity in Input