CVE-2026-24069
Deferred Deferred - Pending Action
Improper Authorization in Kiuwan SAST Enables Disabled User Access

Publication date: 2026-04-14

Last updated on: 2026-05-19

Assigner: SEC Consult Vulnerability Lab

Description
Kiuwan SAST improperly authorizes SSO logins for locally disabled mapped user accounts, allowing disabled users to continue accessing the application. Kiuwan Cloud was affected, and Kiuwan SAST on-premise (KOP) was affected before 2.8.2509.4.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-04-14
Last Modified
2026-05-19
Generated
2026-06-16
AI Q&A
2026-04-14
EPSS Evaluated
2026-06-14
NVD
EUVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
kiuwan kiuwan_cloud to 2.8.2509.4 (exc)
kiuwan kiuwan_sast to 2.8.2509.4 (exc)
kiuwan kiuwan_sast 2.8.2412.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2026-24069 is a vulnerability in Kiuwan SAST's Single Sign-On (SSO) authentication mechanism. It occurs because the system improperly enforces account lockout for locally disabled user accounts that are mapped to SSO users. This means that even if an administrator disables a local Kiuwan user account, the corresponding user can still log in through SSO without restriction.

The issue affects both the cloud and on-premise versions of Kiuwan SAST prior to version 2.8.2509.4. The vulnerability allows users with disabled local accounts to bypass the lockout and access the Kiuwan WebUI via SSO, which should not be possible.

Impact Analysis

This vulnerability can lead to unauthorized access to the Kiuwan WebUI by users whose local accounts have been disabled. Such users can bypass account lockout controls through SSO, potentially gaining access to sensitive information or functionality within the application.

Because disabled accounts are meant to prevent access, this flaw undermines administrative controls and could allow former employees or unauthorized users to continue using the system, posing a medium impact risk.

There is no workaround other than applying the vendor's patch, so immediate updating is strongly recommended to mitigate this risk.

Detection Guidance

This vulnerability involves improper enforcement of locked accounts in the Kiuwan SAST WebUI Single Sign-On (SSO) mechanism, allowing disabled local accounts to still access the application via SSO.

Detection would require verifying whether disabled local Kiuwan accounts can still successfully log in through SSO. Since the issue is specific to the Kiuwan WebUI SSO login process, there are no specific network commands or standard system commands provided to detect this vulnerability.

A practical approach is to attempt logging in via SSO with a locally disabled user account and observe if access is granted. Monitoring authentication logs for successful SSO logins from disabled accounts may also help identify exploitation.

Mitigation Strategies

The vendor strongly recommends immediate installation of the patch that fixes this vulnerability. For Kiuwan SAST on-premise, the fix is included in version 2.8.2509.4, released by November 2025. For the cloud version, the fix was released on July 29, 2025.

No workaround exists other than applying the patch.

Additionally, it is advised to perform a comprehensive security review of the product after patching.

Compliance Impact

The vulnerability allows disabled user accounts to bypass local account lockout and gain unauthorized access to the Kiuwan WebUI via Single Sign-On (SSO). This improper authorization could lead to unauthorized access to sensitive data or systems managed through Kiuwan SAST.

Such unauthorized access risks may impact compliance with common standards and regulations like GDPR and HIPAA, which require strict access controls and protection of sensitive information. Failure to properly enforce account lockouts and prevent unauthorized access could result in violations of these regulations.

Therefore, until the patch is applied, organizations using affected versions of Kiuwan SAST may face increased risk of non-compliance due to this security flaw.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-24069. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart