CVE-2026-24069Disclosure

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Kiuwan SAST improperly authorizes SSO logins for locally disabled mapped user accounts, allowing disabled users to continue accessing the application. Kiuwan Cloud was affected, and Kiuwan SAST on-premise (KOP) was affected before 2.8.2509.4.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-14); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-14: 1Mentions · 2026-04-19: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-19: 104-1404-19
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-141
Disclosure1
2026-04-191
General1
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-24069 Kiuwan SAST improperly authorizes SSO logins for locally disabled mapped user accounts, allowing disabled users to continue accessing the application. Kiuwan Cloud wa… https://www.cve.org/CVERecord?id=CVE-2026-24069

    Post summary

    The text reports that Kiuwan’s SAST platform is vulnerable to SSO authorization bypass for disabled mapped accounts, enabling unauthorized access.

    0000067
    57.2K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『An SSO login is possible even after disabling the Kiuwan mapped user account in the Kiuwan user admin settings.』 CVE-2026-24069 Improper Enforcement of Locked Accounts in WebUI (SSO) in Kiuwan SAST on-premise (KOP) & cloud/SaaS - SEC Consult https://sec-consult.com/vulnerability-lab/advisory/improper-enforcement-of-locked-accounts-in-webui-sso-in-kiuwan-sast-on-premise-kop-cloud-saas/

    Post summary

    The advisory discloses that Kiuwan’s SSO system fails to enforce account lockouts, allowing logins after disabling a mapped user, but no PoC, exploit, patch, or active exploitation claim is included.

    00000412
    6.8K followersView on X

Explore more