CVE 6.5 MEDIUM

Kiteworks MFT has a Privilege Defined With Unsafe Actions_CVE-2025-53900

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Description

Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, an unfavourable definition of roles and permissions in Kiteworks MFT on managing Connections could lead to unexpected escalation of privileges for authorized users. This issue has been patched in version 9.1.0.

Basic Information

ID CVE-2025-53900
Source GitHub_M
Published Nov 29, 2025 at 02:25

Affected Product

Vendor kiteworks
Product security-advisories
Version < 9.1.0
Affected Versions kiteworks security-advisories < 9.1.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.