PT-2025-48362 · Kiteworks · Kiteworks

Published

2025-11-29

·

Updated

2025-11-29

·

CVE-2025-53939

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kiteworks versions prior to 9.1.0
Description Kiteworks is a private data network. Before version 9.1.0, insufficient input validation during the management of shared folder roles could result in unintended privilege escalation for other users on the share.
Recommendations Update to version 9.1.0 or later.

Exploit

Fix

LPE

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-53939
GHSA-HPF5-6376-2565

Affected Products

Kiteworks