CVE-2025-53899: Kiteworks MFT is vulnerable to an Incorrectly Specified Destination in a Communication Channel
Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, the back-end of Kiteworks MFT is vulnerable to an incorrectly specified destination in a communication channel which allows an attacker with administrative privileges on the system under certain circumstances to intercept upstream communication which could lead to an escalation of privileges. This issue has been patched in version 9.1.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53899?
CVE-2025-53899 is considered a high-severity vulnerability due to its potential impact on file transfer security.
How do I fix CVE-2025-53899?
To fix CVE-2025-53899, upgrade Kiteworks MFT to version 9.1.0 or later.
What are the implications of CVE-2025-53899?
CVE-2025-53899 allows attackers with administrative privileges to exploit incorrectly specified destinations in communication channels.
Which versions are affected by CVE-2025-53899?
Versions of Kiteworks MFT prior to 9.1.0 are affected by CVE-2025-53899.
Who is at risk for CVE-2025-53899?
Organizations using Kiteworks MFT versions below 9.1.0 are at risk of exploitation through CVE-2025-53899.