Impact
Affected Kiteworks Core does not apply its gateway‑level API security controls to every request that passes through its central authentication service. This flaw permits an authenticated user to reach REST API functions along an alternate request path that bypasses the enforcement of signed‑out and revoked session checks. The result is an unauthorized ability to access protected resources or perform privileged operations via the bypassed API endpoints, thereby compromising the confidentiality and integrity of the data managed by Kiteworks Core.
Affected Systems
The product impacted is Kiteworks Core. The advisory does not specify affected versions, so all releases of Kiteworks Core are considered vulnerable until the vendor releases a fix.
Risk and Exploitability
With a CVSS score of 5.4 the vulnerability is rated as medium severity. The EPSS score is unavailable, so the exploitation likelihood cannot be precisely quantified, and the vulnerability is not listed in the CISA KEV catalog. The attack requires an authenticated user and the ability to craft a request against the unchecked API path, so the attack scope is limited to users with legitimate credentials but can lead to unauthorized access or privilege escalation. Because the flaw relies on a missing security check rather than a privileged execution flaw, the exploit is less likely to be widespread, but an attacker who gains authenticated access can continue to abuse the same API path for as long as the session remains active.
OpenCVE Enrichment