CVE-2025-53896 is a high-severity vulnerability affecting Kiteworks Managed File Transfer (MFT) versions prior to 9.1.0, where an inactive user session might not properly time out. This flaw could lead to unauthorized access to sensitive data (C:H) and potentially allow for data manipulation (I:H), as indicated by its CVSS score of 8.1. While the vulnerability is easily exploitable over the network with low privileges (AV:N/AC:L/PR:L), there is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.1.0CPE matchmatch criteria | cpe:2.3:a:accellion:kiteworks_managed_file_transfer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.