CVE-2026-24069

MEDIUM

Improper Enforcement of Disabled Accounts in WebUI SSO in Kiuwan SAST

Title source: cna
STIX 2.1

Description

Kiuwan SAST improperly authorizes SSO logins for locally disabled mapped user accounts, allowing disabled users to continue accessing the application. Kiuwan Cloud was affected, and Kiuwan SAST on-premise (KOP) was affected before 2.8.2509.4.

Scores

CVSS v3 5.4
EPSS 0.0001
EPSS Percentile 1.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (1)
Kiuwan/SAST <2.8.2509.4
Published Apr 14, 2026
Tracked Since Apr 14, 2026