Missing Authorization in Kiwi - #VU154040

 

Missing Authorization in Kiwi - #VU154040

Published: October 9, 2026


Vulnerability identifier: #VU154040
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authorization checks.

The vulnerability exists due to missing email ownership confirmation within User.update API method. A remote user can change an account's email address without confirming ownership of the new address and bypass the email verification mechanism.


Affected software

Kiwi

Remediation

Install updates from vendor's website.

Kiwi - update to 16.6

External References

Related Security Bulletins