OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102093

HIGH · CVSS 7.2 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

Kiteworks Core versions prior to 9.5.0 are susceptible to improper privilege management, enabling authenticated administrative users with limited permissions to improperly elevate other users to full system-administrator privileges. This vulnerability poses a significant risk as it can lead to unauthorized access and control over sensitive system functions. Organizations using Kiteworks Core should prioritize patching to mitigate the potential for privilege escalation and ensure proper role enforcement.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102093
Severity
HIGH
CVSS
7.2
EPSS
0.34%

Original NVD Description

Kiteworks Core before version 9.5.0 is vulnerable to Improper Privilege Management and does not correctly enforce restrictions on role assignment, which could allow an authenticated administrative user with limited, non-Sysadmin role-management permissions to elevate another user to full system-administrator privileges beyond those the administrative user was authorized to grant.

Related CVEs

Other vulnerabilities affecting the same vendor(s)