CVE-2026-102107
- EPSS 0.16%
- Veröffentlicht 30.09.2026 20:24:29
- Zuletzt bearbeitet 07.10.2026 13:55:07
Kiteworks Core contains a business logic flaw in a Kiteworks file-request feature allowed an authenticated user to send a request that appeared to originate from another user, because the server did not verify that the requester was authorized to act...
CVE-2026-102111
- EPSS 0.21%
- Veröffentlicht 30.09.2026 20:21:15
- Zuletzt bearbeitet 07.10.2026 13:55:45
Kiteworks did not enforce the maximum permitted value for a configurable security-policy setting. An authenticated administrator could set this value outside its intended range so that the associated control never activated, while the control continu...
CVE-2026-102112
- EPSS 0.12%
- Veröffentlicht 30.09.2026 20:20:59
- Zuletzt bearbeitet 07.10.2026 13:56:12
A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root and run arbitrary commands with the highest privileges. ...
CVE-2026-102113
- EPSS 0.13%
- Veröffentlicht 30.09.2026 20:20:35
- Zuletzt bearbeitet 07.10.2026 13:56:33
A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root. A privileged routine did not safely handle a filesystem...
CVE-2026-102114
- EPSS 1.03%
- Veröffentlicht 30.09.2026 20:20:18
- Zuletzt bearbeitet 07.10.2026 13:57:03
A command injection vulnerability in Kiteworks could allow a high-privileged authenticated administrator to execute arbitrary operating-system commands as root on the affected appliance node. Successful exploitation requires an administrative account...
CVE-2026-102115
- EPSS 0.33%
- Veröffentlicht 30.09.2026 20:19:55
- Zuletzt bearbeitet 07.10.2026 13:57:31
Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who knew the email address of a user with a locally stored password could potentially reset that account's password without ac...
CVE-2026-102118
- EPSS 0.13%
- Veröffentlicht 30.09.2026 20:18:21
- Zuletzt bearbeitet 07.10.2026 13:58:08
A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an existing shell under a low-privileged service account to escalate to root privileges on the appliance.
CVE-2026-102120
- EPSS 0.14%
- Veröffentlicht 30.09.2026 20:17:48
- Zuletzt bearbeitet 07.10.2026 13:58:34
A privilege escalation vulnerability in Kiteworks could have allowed an attacker who had already obtained code execution on one node of a clustered Kiteworks deployment to run operating system commands with elevated privileges on another node of the ...
CVE-2026-102122
- EPSS 0.16%
- Veröffentlicht 30.09.2026 20:16:24
- Zuletzt bearbeitet 07.10.2026 14:03:35
Kiteworks did not correctly enforce which roles a shared folder's manager was permitted to assign. In a default configuration, an authenticated user holding the Manager role on a folder could grant the Owner role to themselves or to other members of ...
CVE-2026-102123
- EPSS 0.32%
- Veröffentlicht 30.09.2026 20:16:01
- Zuletzt bearbeitet 07.10.2026 14:08:29
A Kiteworks appliance setup interface did not confine a user-supplied file path to its intended directory, which could allow an unauthenticated attacker to write a file to any location writable by the affected service account, potentially compromisin...