Impact
An administrative import function in Kiteworks Core fails to confirm that the requesting administrator has the right to create the privileged integration credential being imported. A delegated administrator who holds only a single, narrowly scoped permission can therefore create a credential that grants full system administrator privileges, bypassing review or approval from an existing system administrator. If exploited, the attacker would gain complete control over the system, enabling them to read, modify, or delete any data, disable security controls, or disrupt service. The weakness is a classic access control flaw.
Affected Systems
This flaw exists in all versions of Kiteworks Core that include the import functionality, and any deployment where at least one delegated administrator has the narrow permission to create privileged integration credentials. No specific version numbers are listed, so all installations using this feature are potentially impacted.
Risk and Exploitability
The vulnerability is cited as CWE‑284 and carries a CVSS score of 7.2, indicating medium-to-high potential impact due to the full elevation of privileges it allows. No EPSS score is available, and the issue is not currently listed in CISA’s KEV catalog, suggesting it is not actively exploited in the wild yet. The attack vector is primarily internal: an attacker must first obtain delegated administrative access that has the restricted permission but can leverage the import function to elevate that privilege. Because the flaw does not rely on external exploitation of network services or user interaction, the likelihood of discovery and use may increase in environments where delegated administrators are common. Immediate remediation is recommended until an official vendor fix or workaround is released.
OpenCVE Enrichment