CVE-2026-102122
MediumPublished
Kiteworks Core Incorrect Authorization
- Published
- Sep 30, 2026
- Updated
- Oct 1, 2026
- Assigning CNA
- cisa-cg
- Evidence observed
- Oct 1, 2026
Primary CVSS
4.3/ 10Medium
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NSummary
Kiteworks did not correctly enforce which roles a shared folder's manager was permitted to assign. In a default configuration, an authenticated user holding the Manager role on a folder could grant the Owner role to themselves or to other members of that folder.
Sources
A community-curated, verified collection of Proof-of-Concept exploits for CVEs disclosed in 2026.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.