Kiuwan SAST improperly authorizes SSO logins for locally disabled mapped user accounts, allowing disabled users to continue accessing the application. Kiuwan Cloud was affected, and Kiuwan SAST on-premise (KOP) was affected before 2.8.2509.4.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
The issue was fixed for Kiuwan Cloud on 29 July 2025. For Kiuwan SAST on-premise (KOP), the issue is fixed in version 2.8.2509.4.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://r.sec-consult.com/kiuwanlock |
|
History
Tue, 14 Apr 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kiuwan SAST improperly authorizes SSO logins for locally disabled mapped user accounts, allowing disabled users to continue accessing the application. Kiuwan Cloud was affected, and Kiuwan SAST on-premise (KOP) was affected before 2.8.2509.4. | |
| Title | Improper Enforcement of Disabled Accounts in WebUI SSO in Kiuwan SAST | |
| Weaknesses | CWE-863 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: SEC-VLab
Published:
Updated: 2026-04-14T15:45:49.812Z
Reserved: 2026-01-21T11:29:19.854Z
Link: CVE-2026-24069
No data.
Status : Received
Published: 2026-04-14T12:16:20.247
Modified: 2026-04-14T12:16:20.247
Link: CVE-2026-24069
No data.
OpenCVE Enrichment
No data.
Weaknesses