Description
An administrative import function in Kiteworks Core did not verify that the requesting administrator was entitled to create the privileged integration credential being imported. A delegated administrator holding a single narrowly scoped administrative permission could therefore obtain full system administrator privileges, without any action by an existing system administrator.
Published: 2026-09-30
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Patch ASAP
AI Analysis

Impact

An administrative import function in Kiteworks Core fails to confirm that the requesting administrator has the right to create the privileged integration credential being imported. A delegated administrator who holds only a single, narrowly scoped permission can therefore create a credential that grants full system administrator privileges, bypassing review or approval from an existing system administrator. If exploited, the attacker would gain complete control over the system, enabling them to read, modify, or delete any data, disable security controls, or disrupt service. The weakness is a classic access control flaw.

Affected Systems

This flaw exists in all versions of Kiteworks Core that include the import functionality, and any deployment where at least one delegated administrator has the narrow permission to create privileged integration credentials. No specific version numbers are listed, so all installations using this feature are potentially impacted.

Risk and Exploitability

The vulnerability is cited as CWE‑284 and carries a CVSS score of 7.2, indicating medium-to-high potential impact due to the full elevation of privileges it allows. No EPSS score is available, and the issue is not currently listed in CISA’s KEV catalog, suggesting it is not actively exploited in the wild yet. The attack vector is primarily internal: an attacker must first obtain delegated administrative access that has the restricted permission but can leverage the import function to elevate that privilege. Because the flaw does not rely on external exploitation of network services or user interaction, the likelihood of discovery and use may increase in environments where delegated administrators are common. Immediate remediation is recommended until an official vendor fix or workaround is released.

Generated by OpenCVE AI on September 30, 2026 at 23:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Restrict delegated administrator permissions so they cannot create privileged integration credentials
  • Enable detailed logging of import actions and monitor for abnormal privilege changes
  • Stay informed of vendor advisories and apply any released patch as soon as it becomes available

Generated by OpenCVE AI on September 30, 2026 at 23:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Kiteworks
Kiteworks core
Vendors & Products Kiteworks
Kiteworks core

Wed, 30 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description An administrative import function in Kiteworks Core did not verify that the requesting administrator was entitled to create the privileged integration credential being imported. A delegated administrator holding a single narrowly scoped administrative permission could therefore obtain full system administrator privileges, without any action by an existing system administrator.
Title Kiteworks Core Privilege Escalation through Improper Access Control
Weaknesses CWE-284
References

cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-09-30T20:38:31.422Z

Reserved: 2026-09-28T17:39:13.563Z

Link: CVE-2026-102132

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T21:17:01.787

Modified: 2026-10-01T02:17:43.350

Link: CVE-2026-102132

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T06:00:13Z

Weaknesses