CVE-2026-24069: Kiuwan Sast
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Kiuwan SAST improperly authorizes SSO logins for locally disabled mapped user accounts, allowing disabled users to continue accessing the application. Kiuwan Cloud was affected, and Kiuwan SAST on-premise (KOP) was affected before 2.8.2509.4.
Affected products
- Kiuwan Sast: before 2.8.2509.4 (fixed in 2.8.2509.4)
Published 2026-04-14. Last modified 2026-06-17.