PT-2026-103565 · Kiteworks · Kiteworks Core

·

CVE-2026-102132

·

Published

2026-09-30

·

Updated

2026-10-01

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kiteworks Core (affected versions not specified)
Description An administrative import function fails to verify if the requesting administrator has the necessary permissions to create the privileged integration credential being imported. This allows a delegated administrator with limited permissions to escalate their privileges to full system administrator status without requiring action from an existing system administrator.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102132

Affected Products

Kiteworks Core