admin/Auth in OpenKM 5.1.7 and other versions before 5.1.8-2 does not properly enforce privileges for changing user roles, which allows remote authenticated users to assign administrator privileges to arbitrary users via the userEdit action.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.072
EPSS Ranking 91.8%