Impact
Kiteworks Core does not correctly enforce the role‑assignment permissions for shared folder managers. A user who holds the Manager role on a folder can assign the Owner role to themselves or to any other member of that folder. This bypasses the intended authorization controls and gives the Manager or the newly promoted owner elevated access, permitting them to modify or delete shared‑folder contents and alter sharing settings without proper approval.
Affected Systems
The affected product is Kiteworks Core. All versions that use the default role‑enforcement configuration are susceptible; no specific version range is listed in the advisory.
Risk and Exploitability
The vulnerability receives a CVSS score of 4.3, indicating moderate impact for those who are able to authenticate as a folder manager. The EPSS score is unavailable and the vulnerability is not listed in CISA’s KEV catalog, suggesting low likelihood of widespread exploitation. It requires a valid, authenticated Manager account; the attacker needs to be a member of a shared folder with Manager rights, after which they can elevate themselves or other members to Owner. The attack is therefore constrained to the scope of that folder and does not provide broader system compromise.
OpenCVE Enrichment