CVE-2026-102132 UNKNOWN

CVE-2026-102132

Published: 2026-09-30

Description

An administrative import function in Kiteworks Core did not verify that the requesting administrator was entitled to create the privileged integration credential being imported. A delegated administrator holding a single narrowly scoped administrative permission could therefore obtain full system administrator privileges, without any action by an existing system administrator.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…