CVE-2026-102093
Received Received - Intake

Improper Privilege Management in Kiteworks Core

Vulnerability report for CVE-2026-102093, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Description

Kiteworks Core before version 9.5.0 is vulnerable to Improper Privilege Management and does not correctly enforce restrictions on role assignment, which could allow an authenticated administrative user with limited, non-Sysadmin role-management permissions to elevate another user to full system-administrator privileges beyond those the administrative user was authorized to grant.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
kiteworks core to 9.5.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Kiteworks Core before version 9.5.0 has a flaw where administrative users with limited permissions can incorrectly assign full system administrator privileges to other users. This improper privilege management allows privilege escalation beyond authorized limits.

Impact Analysis

An attacker with administrative access could exploit this to grant themselves or others full system control, bypassing intended restrictions. This could lead to unauthorized data access, system manipulation, or complete compromise of the Kiteworks Core environment.

Compliance Impact

This vulnerability could violate compliance requirements that mandate strict access controls and least privilege principles. Unauthorized privilege escalation risks exposing sensitive data, leading to potential violations of GDPR, HIPAA, or other regulatory frameworks.

Mitigation Strategies

Immediately update Kiteworks Core to version 9.5.0 or later to address the privilege management flaw. Review all user roles and permissions to ensure no unauthorized privilege escalations have occurred. Restrict administrative user permissions to the minimum required for their tasks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102093. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart