kiteworks_managed_file_transfer vulnerabilities
CVEs whose affected-version data names the kiteworks_managed_file_transfer package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2025-53900Medium· 6.5Kiteworks MFT orchestrates end-to-end file transfer workflows
Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, an unfavourable definition of roles and permissions in Kiteworks MFT on managing Connections could lead to unexpected escalation of privileges for aut…
CVE-2025-53899High· 7.2Kiteworks MFT orchestrates end-to-end file transfer workflows
Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, the back-end of Kiteworks MFT is vulnerable to an incorrectly specified destination in a communication channel which allows an attacker with administr…
CVE-2025-53897Medium· 6.8Kiteworks MFT orchestrates end-to-end file transfer workflows
Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, this vulnerability could allow an external attacker to gain access to log information from the system by tricking an administrator into browsing a spe…
CVE-2025-53896High· 7.1Kiteworks MFT orchestrates end-to-end file transfer workflows
Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, a bug in Kiteworks MFT could cause under certain circumstances that a user's active session would not properly time out due to inactivity. This issue …