CVE-2026-102129

high

Description

A user-provisioning interface in Kiteworks Core did not verify that the requesting administrator was entitled to grant the role being assigned. An administrator whose delegated permissions covered role changes alone could therefore raise an account to full system-administrator privileges.

References

https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json

https://github.com/kiteworks/security-advisories/security/advisories/GHSA-4gcf-w86v-34rp

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-90288

Details

Source: Mitre, NVD

Published: 2026-09-30

Updated: 2026-10-08

Risk Information

CVSS v2

Base Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:M/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 7.2

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00836