OFFLINE
Awaiting data
Security intelligence
MinorCritical vulnerability

CVE-2026-102129 (CVSS 7.2)

NVD · officialPublished Sep 30, 2026Risk 23/100

A user-provisioning interface in Kiteworks Core did not verify that the requesting administrator was entitled to grant the role being assigned. An administrator whose delegated permissions covered role changes alone could therefore raise an account to full system-administrator privileges.

CVSS
7.2
AV:NetworkAC:LowPR:HighUI:NoneC:HighI:HighA:High

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source