HIGH🇵🇱 Wersja polska

CVE-2025-53899

CVSS 7.2v3.1pub. 2025-11-29upd. 2025-12-03

Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, the back-end of Kiteworks MFT is vulnerable to an incorrectly specified destination in a communication channel which allows an attacker with administrative privileges on the system under certain circumstances to intercept upstream communication which could lead to an escalation of privileges. This issue has been patched in version 9.1.0.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Accellion Kiteworks Managed File Transfer

    APP
    Accellion
    < 9.1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-53896HIGH7.1same product

Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, a bug in Kiteworks MFT ...

CVE-2025-53897MEDIUM6.8same product

Kiteworks MFT organizuje end-to-end przepływy przesyłania plików. Przed wersją 9.1.0 ta luka mogła pozwolić ze...

CVE-2025-53900MEDIUM6.5same product

Kiteworks MFT organizuje kompleksowe przepływy pracy transferu plików. Przed wersją 9.1.0 nieprawidłowa defini...

CVE-2021-27101CRITICAL9.8⚠ KEVPL ✓same vendor

SQL injection w Accellion FTA przez nagłówek Host w żądaniu HTTP

CVE-2021-27103CRITICAL9.8⚠ KEVPL ✓same vendor

SSRF w Accellion FTA via wmProgressstat.html — zdalne fałszowanie żądań