CVE-2025-53900

MEDIUM

Kiteworks MFT <9.1.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, an unfavourable definition of roles and permissions in Kiteworks MFT on managing Connections could lead to unexpected escalation of privileges for authorized users. This issue has been patched in version 9.1.0.

Scores

CVSS v3 6.5
EPSS 0.0003
EPSS Percentile 8.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-267
Status published
Products (1)
accellion/kiteworks_managed_file_transfer < 9.1.0
Published Nov 29, 2025
Tracked Since Feb 18, 2026