CVE-2025-53939: Kiteworks Core is vulnerable to Improper Input Validation
Published Nov 29, 2025
·Updated
Kiteworks is a private data network (PDN). Prior to version 9.1.0, improper input validation when managing roles of a shared folder could lead to unexpectedly elevate another user's permissions on the share. This issue has been patched in version 9.1.0.
Affected Software
2 affected components
Kiteworks Core<9.1.0
Accellion Kiteworks<9.1.0
Remediation
Event History
Nov 29, 2025
CVE Published
via MITRE·02:25 AM
Data Sourced
via MITRE·02:25 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-53939?
The severity of CVE-2025-53939 is considered critical due to the potential for unauthorized privilege escalation.
2
How do I fix CVE-2025-53939?
To fix CVE-2025-53939, update to Kiteworks Core version 9.1.0 or later.
3
What are the implications of CVE-2025-53939 for users?
Implications of CVE-2025-53939 for users include the risk of unauthorized access to shared folders and sensitive data.
4
Is CVE-2025-53939 exploitable remotely?
Yes, CVE-2025-53939 is exploitable remotely if the affected software is accessible over a network.
5
Which versions of Kiteworks are affected by CVE-2025-53939?
Versions of Kiteworks Core prior to 9.1.0 are affected by CVE-2025-53939.