CVE-2026-102093: Kiteworks Core improper privilege management
Kiteworks Core before version 9.5.0 is vulnerable to Improper Privilege Management and does not correctly enforce restrictions on role assignment, which could allow an authenticated administrative user with limited, non-Sysadmin role-management permissions to elevate another user to full system-administrator privileges beyond those the administrative user was authorized to grant.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Kiteworks Coreto a version that resolves this vulnerability.Fixed in 9.5.0
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated administrative user who has limited, non-Sysadmin role-management permissions can exploit the issue. Exploitation does not require user interaction.
What level of access can an attacker obtain?
The attacker can elevate another user to full system-administrator privileges, exceeding the privileges the attacker is authorized to grant. The listed impacts include high confidentiality, integrity, and availability impact.
Which deployments are affected?
Kiteworks Core versions before 9.5.0 are affected. The provided information does not identify any configuration-based exception.
What is the immediate mitigation if upgrading cannot be completed?
The provided information does not specify a workaround. Limit role-management permissions to trusted administrators and review role assignments for unauthorized grants of full system-administrator privileges.