PT-2025-7788 · Kiteworks · Kiteworks Mft

Published

2025-02-24

·

Updated

2025-12-03

·

CVE-2025-53900

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kiteworks MFT versions prior to 9.1.0
Description An improper definition of roles and permissions in Kiteworks MFT regarding the management of Connections could allow authorized users to unexpectedly escalate privileges. This affects file transfer workflows orchestrated by Kiteworks MFT.
Recommendations Update to version 9.1.0 or later.

Exploit

Fix

LPE

Weakness Enumeration

Related Identifiers

CVE-2025-53900
GHSA-GJQ3-8V6P-2H6H

Affected Products

Kiteworks Mft