---
id: CVE-2026-102129
title: >-
  A user-provisioning interface in Kiteworks Core did not verify that the
  requesting administrator was entitled to grant the role being assigned
summary: >-
  A user-provisioning interface in Kiteworks Core did not verify that the
  requesting administrator was entitled to grant the role being assigned. An
  administrator whose delegated permissions covered role changes alone could
  therefore raise…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-266
vendor: Kiteworks
product: Core
affected:
  - Core < 9.5.1
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:17:01.407'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102129'
references:
  - url: >-
      https://github.com/kiteworks/security-advisories/security/advisories/GHSA-4gcf-w86v-34rp
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T21:25:07.832Z'
---

## Overview

A user-provisioning interface in Kiteworks Core did not verify that the requesting administrator was entitled to grant the role being assigned. An administrator whose delegated permissions covered role changes alone could therefore raise an account to full system-administrator privileges.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
