Description
A user-provisioning interface in Kiteworks Core did not verify that the requesting administrator was entitled to grant the role being assigned. An administrator whose delegated permissions covered role changes alone could therefore raise an account to full system-administrator privileges.
Published: 2026-09-30
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

A user‑provisioning interface in Kiteworks Core fails to verify that the administrator requesting a role change is authorized to assign that role. An administrator who has been delegated only the ability to alter user roles could therefore elevate any account to a full system‑administrator, giving them unrestricted access to the entire system. This flaw directly corresponds to an Authorization Bypass through Privilege Assignment weakness.

Affected Systems

Kiteworks Core is the affected product. No specific version information is provided, so any publicly released version of the core system that contains the buggy provisioning interface could be vulnerable.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that the exploitation likelihood is uncertain but potentially significant. Based on the description, the likely attack vector requires an attacker to be an authenticated administrator with delegated role‑change permissions. If such credentials are obtained—either through credential compromise or malicious insider actions—the admin could raise the privileges of any account to full system‑administrator level.

Generated by OpenCVE AI on September 30, 2026 at 22:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Kiteworks Core to the latest supported release that implements the proper privilege verification.
  • Audit and restrict any delegated permissions that allow role changes, ensuring that administrators can only assign roles they are expressly authorized to grant.
  • Re‑review existing role assignments and remove any over‑privileged accounts that may have been created through this flaw.

Generated by OpenCVE AI on September 30, 2026 at 22:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Kiteworks
Kiteworks core
Vendors & Products Kiteworks
Kiteworks core

Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A user-provisioning interface in Kiteworks Core did not verify that the requesting administrator was entitled to grant the role being assigned. An administrator whose delegated permissions covered role changes alone could therefore raise an account to full system-administrator privileges.
Title Kiteworks Core Incorrect Privilege Assignment
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-09-30T20:14:13.681Z

Reserved: 2026-09-28T17:39:13.563Z

Link: CVE-2026-102129

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T21:17:01.407

Modified: 2026-10-01T02:17:43.350

Link: CVE-2026-102129

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T06:00:13Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment