Impact
A user‑provisioning interface in Kiteworks Core fails to verify that the administrator requesting a role change is authorized to assign that role. An administrator who has been delegated only the ability to alter user roles could therefore elevate any account to a full system‑administrator, giving them unrestricted access to the entire system. This flaw directly corresponds to an Authorization Bypass through Privilege Assignment weakness.
Affected Systems
Kiteworks Core is the affected product. No specific version information is provided, so any publicly released version of the core system that contains the buggy provisioning interface could be vulnerable.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that the exploitation likelihood is uncertain but potentially significant. Based on the description, the likely attack vector requires an attacker to be an authenticated administrator with delegated role‑change permissions. If such credentials are obtained—either through credential compromise or malicious insider actions—the admin could raise the privileges of any account to full system‑administrator level.
OpenCVE Enrichment