Description
Kiuwan SAST improperly authorizes SSO logins for locally disabled mapped user accounts, allowing disabled users to continue accessing the application. Kiuwan Cloud was affected, and Kiuwan SAST on-premise (KOP) was affected before 2.8.2509.4.
Problem types
CWE-863 Incorrect Authorization
Product status
<2.8.2509.4
Credits
Bernhard Gründling, SEC Consult Vulnerability Lab
Fabian Würfl, SEC Consult Vulnerability Lab
Johannes Greil, SEC Consult Vulnerability Lab
References
seclists.org/fulldisclosure/2026/Apr/5
r.sec-consult.com/kiuwanlock