Impact
The vulnerability originates from a failure to enforce the maximum permitted value for a configurable security-policy setting. An authenticated administrator can set this value beyond its intended limits, causing the associated enforcement control to remain inactive while the user interface and audit logs indicate that the control is active. This silent disabling allows subsequent privileged actions to bypass the intended security check without detection.
Affected Systems
All deployments of Kiteworks Core are potentially affected because the flaw exists in the core configuration handling. No specific version numbers are disclosed in the advisory, so administrators should treat every installation as a candidate for review until a patched version becomes available.
Risk and Exploitability
The CVSS score of 4.9 signifies moderate impact, and the exploitation vector is limited to administrators with valid credentials, as the attacker must first change a configuration value. EPSS is not available and the vulnerability is not listed in CISA KEV, indicating that widespread exploitation has not been observed. However, the flaw could be leveraged by a malicious or compromised administrator to silently disable an important control, thus potentially compromising data integrity or confidentiality.
OpenCVE Enrichment