CVE-2026-102129
Received Received - Intake

Privilege Escalation in Kiteworks Core

Vulnerability report for CVE-2026-102129, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Description

A user-provisioning interface in Kiteworks Core did not verify that the requesting administrator was entitled to grant the role being assigned. An administrator whose delegated permissions covered role changes alone could therefore raise an account to full system-administrator privileges.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-266 A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a flaw in Kiteworks Core's user-provisioning interface. It allows an administrator with limited delegated permissions to assign full system-administrator privileges to an account. The issue occurs because the system fails to verify if the requesting administrator is authorized to grant the specific role being assigned.

Impact Analysis

This vulnerability could allow an attacker with limited administrative access to escalate their privileges to full system control. This could lead to unauthorized access to sensitive data, system manipulation, or further compromise of the entire infrastructure.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements for GDPR, HIPAA, and other regulations. It undermines access control and audit mechanisms, potentially resulting in data breaches and non-compliance penalties.

Mitigation Strategies

Review administrator roles and permissions to ensure no account has excessive delegated rights. Remove any ability for non-full-administrators to grant full system-administrator privileges. Apply vendor patches or updates for Kiteworks Core immediately.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102129. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart