OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102129

HIGH · CVSS 7.2 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

A vulnerability in the user-provisioning interface of Kiteworks Core allows an administrator with limited delegated permissions to elevate user roles to full system-administrator privileges without proper verification. This flaw poses a significant risk, as it could lead to unauthorized access and control over the system. Organizations utilizing Kiteworks Core should prioritize remediation to mitigate potential exploitation of this privilege escalation issue.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102129
Severity
HIGH
CVSS
7.2
EPSS
0.27%

Original NVD Description

A user-provisioning interface in Kiteworks Core did not verify that the requesting administrator was entitled to grant the role being assigned. An administrator whose delegated permissions covered role changes alone could therefore raise an account to full system-administrator privileges.