CVE-2025-53899
Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, the back-end of Kiteworks MFT is vulnerable to an incorrectly specified destination in a communication channel which allows an attacker with administrative privileges on the system under certain circumstances to intercept upstream communication which could lead to an escalation of privileges. This issue has been patched in version 9.1.0.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.2
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.94%
- CWE
- CWE-941
- Published
- 2025-11-29
- Last modified
- 2026-03-13
Affected products
- kiteworks security-advisories
Weakness type
Related vulnerabilities
- CVE-2026-72506 — VoiceTra provided by National Institute of Information and Communications Technology (NICT)...
- CVE-2026-69246 — Guzzle: Noncanonical host can bypass host-based checks
- CVE-2026-40118 — UDP Console provided by Arcserve contains an incorrectly specified destination in a communication...
- CVE-2025-0036 — In AMD Versal Adaptive SoC devices, the incorrect configuration of the SSS during runtime...
- CVE-2023-33198 — Incorrectly Specified Chat Message Destinations in tgstation-server and DreamMaker API
- CVE-2022-4847 — Incorrectly Specified Destination in a Communication Channel in usememos/memos
- CVE-2019-18242 — In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility,...