Description
Kiteworks did not correctly enforce which roles a shared folder's manager was permitted to assign. In a default configuration, an authenticated user holding the Manager role on a folder could grant the Owner role to themselves or to other members of that folder.
Published: 2026-09-30
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Assess Impact
AI Analysis

Impact

Kiteworks Core does not correctly enforce the role‑assignment permissions for shared folder managers. A user who holds the Manager role on a folder can assign the Owner role to themselves or to any other member of that folder. This bypasses the intended authorization controls and gives the Manager or the newly promoted owner elevated access, permitting them to modify or delete shared‑folder contents and alter sharing settings without proper approval.

Affected Systems

The affected product is Kiteworks Core. All versions that use the default role‑enforcement configuration are susceptible; no specific version range is listed in the advisory.

Risk and Exploitability

The vulnerability receives a CVSS score of 4.3, indicating moderate impact for those who are able to authenticate as a folder manager. The EPSS score is unavailable and the vulnerability is not listed in CISA’s KEV catalog, suggesting low likelihood of widespread exploitation. It requires a valid, authenticated Manager account; the attacker needs to be a member of a shared folder with Manager rights, after which they can elevate themselves or other members to Owner. The attack is therefore constrained to the scope of that folder and does not provide broader system compromise.

Generated by OpenCVE AI on September 30, 2026 at 21:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑released patch or upgrade to a fixed release of Kiteworks Core that resolves the role‑assignment issue.
  • Restrict the ability of Manager‑role users to assign the Owner role by configuring folder‑permission policies or removing the self‑promotion capability.
  • Audit all existing shared folders to verify that no Manager has improperly assigned the Owner role to themselves or other users, and revoke any unauthorized Owner privileges.

Generated by OpenCVE AI on September 30, 2026 at 21:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
First Time appeared Kiteworks
Kiteworks core
Vendors & Products Kiteworks
Kiteworks core

Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description Kiteworks did not correctly enforce which roles a shared folder's manager was permitted to assign. In a default configuration, an authenticated user holding the Manager role on a folder could grant the Owner role to themselves or to other members of that folder.
Title Kiteworks Core Incorrect Authorization
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-09-30T20:16:24.341Z

Reserved: 2026-09-28T17:39:13.562Z

Link: CVE-2026-102122

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T21:17:00.370

Modified: 2026-10-01T02:17:43.350

Link: CVE-2026-102122

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T05:30:17Z

Weaknesses