VDB
CVE-2026-102129
CVE-2026-102129
PUBLISHED
CVSS 7.2 HIGH
Reported by cisa-cg · Published September 30, 2026
A user-provisioning interface in Kiteworks Core did not verify that the requesting administrator was entitled to grant the role being assigned. An administrator whose delegated permissions covered role changes alone could therefore raise an account to full system-administrator privileges.
Risk Scores
CVSS 3.1
7.2
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kiteworks | Core | 0, 9.5.1 |
| Kiteworks | Core | 0, 9.5.1, 0 |
Timeline
- Sep 30, 2026 Coalition ESS Score
- Sep 30, 2026 CVE Published
- Oct 1, 2026 EPSS Score
- Oct 2, 2026 EPSS Score
- Oct 6, 2026 EPSS Score
- Oct 8, 2026 CVE Updated