LiveActive security incident?Get immediate response
CVE Record

CVE-2021-31586: Accellion Kiteworks before 7.4.0 allows an authenticated user to perform SQL Injection via LDAPGroup Search.

Accellion Kiteworks before 7.4.0 allows an authenticated user to perform SQL Injection via LDAPGroup Search.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

CVE-2021-31586 is an authenticated SQL injection issue in Accellion Kiteworks before version 7.4.0. A logged-in user could misuse LDAPGroup Search to manipulate database queries. The public sources do not provide CVSS, detailed impact, or exploit details.

Executive priority

Treat this as a priority remediation if Kiteworks is deployed below 7.4.0. The issue requires authentication, but the affected product handles sensitive file-transfer workflows, and public sources do not narrow the impact enough to justify delay.

Technical view

The vulnerability affects Accellion Kiteworks versions before 7.4.0 and is triggered through LDAPGroup Search by an authenticated user. The sources identify SQL injection but do not describe privileges required beyond authentication, reachable roles, database impact, or affected deployment configurations.

Likely exposure

Organizations running Accellion Kiteworks before 7.4.0 are potentially exposed, especially where authenticated users can access LDAPGroup Search. Exposure depends on product version, enabled LDAP integration, and user permissions, which the sources do not fully define.

Exploitation context

CISA KEV status is false in the provided bundle, and no cited source states active exploitation. The issue still matters because SQL injection in an authenticated enterprise file-sharing platform can threaten sensitive data if reachable by low-trust users.

Researcher notes

Evidence is sparse. Sources confirm an authenticated SQL injection via LDAPGroup Search in Kiteworks before 7.4.0, but omit CVSS, CWE, role requirements, endpoint detail, exploit status, and database impact. Avoid assumptions beyond authenticated SQL injection and version boundary.

Mitigation direction

  • Upgrade Kiteworks to 7.4.0 or later where vendor guidance supports it.
  • Review Accellion/Kiteworks advisories for any additional fixed builds or configuration guidance.
  • Limit LDAPGroup Search access to trusted administrative users only.
  • Monitor Kiteworks and database logs for unusual LDAPGroup Search activity.

Validation and detection

  • Inventory all Kiteworks deployments and confirm exact product versions.
  • Check whether LDAP integration and LDAPGroup Search are enabled.
  • Review which authenticated roles can reach LDAPGroup Search.
  • Confirm remediation by verifying the deployment is not before version 7.4.0.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

description · low confidence lookup

Database behavior lookup

The CVE wording references database injection or access, so collection and exfiltration review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2021-31586 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.