Full Disclosure mailing list archives
SEC Consult SA-20260414-0 :: Improper Enforcement of Locked Accounts in WebUI (SSO) in Kiuwan SAST on-premise (KOP) & cloud/SaaS
From: SEC Consult Vulnerability Lab via Fulldisclosure
Date: Tue, 14 Apr 2026 10:31:18 +0000
SEC Consult Vulnerability Lab Security Advisory < 20260414-0 > ============================================...
The strongest version of this narrative is that a legitimate security vulnerability was responsibly disclosed, acknowledged, and patched by the vendor. The researchers followed ethical disclosure practices, and the vendor responded appropriately, albeit with some delays in the on-premise fix. The vulnerability itself is a clear example of inconsistent security controls—where one part of the system (KLA) enforces account lockout while another (WebUI) does not. This inconsistency could lead to una...
