CVE-2026-102126
- EPSS 0.22%
- Veröffentlicht 30.09.2026 20:15:09
- Zuletzt bearbeitet 07.10.2026 14:10:17
A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an administrator holding only a single, narrowly scoped delegated permission to store crafted content that later executes arbitrary JavaScript in the authenticated session of ...
CVE-2026-102132
- EPSS 0.34%
- Veröffentlicht 30.09.2026 20:13:28
- Zuletzt bearbeitet 07.10.2026 14:09:53
An administrative import function in Kiteworks Core did not verify that the requesting administrator was entitled to create the privileged integration credential being imported. A delegated administrator holding a single narrowly scoped administrativ...
CVE-2026-102134
- EPSS 0.21%
- Veröffentlicht 30.09.2026 20:12:39
- Zuletzt bearbeitet 07.10.2026 14:09:28
Kiteworks Core did not apply its gateway-level API security controls to every request authenticated through the platform's central authentication service. An authenticated user could reach REST API functionality over a request path on which those con...
CVE-2026-102101
- EPSS 0.31%
- Veröffentlicht 30.09.2026 20:11:24
- Zuletzt bearbeitet 07.10.2026 13:25:15
Kiteworks Core before version 9.5.0 is vulnerable to Deserialization of Untrusted Data. A deserialization weakness in Kiteworks Core could, under certain conditions, allow crafted data to be deserialized unsafely, potentially resulting in remote code...
CVE-2026-102139
- EPSS 0.26%
- Veröffentlicht 30.09.2026 20:11:17
- Zuletzt bearbeitet 07.10.2026 15:01:35
An authorization check in the large file exchange feature of Kiteworks Email Protection Gateway did not correctly establish that the requesting user was a party to the package being requested. An authenticated user of that optional feature could read...
CVE-2026-102141
- EPSS 0.1%
- Veröffentlicht 30.09.2026 20:10:55
- Zuletzt bearbeitet 07.10.2026 16:17:32
Two Kiteworks Core cluster-management operations did not validate file paths supplied to them, so an attacker holding root on one node of a cluster could write files as root onto another node and cause them to be executed there. Exploitation requires...
CVE-2026-102142
- EPSS 0.39%
- Veröffentlicht 30.09.2026 20:10:30
- Zuletzt bearbeitet 07.10.2026 15:02:00
A system notification template on the Kiteworks appliance was rendered by a template engine that evaluated expressions contained in the stored template body. An authenticated System Administrator could potentially store a crafted template that execut...
CVE-2026-102100
- EPSS 0.22%
- Veröffentlicht 30.09.2026 20:10:05
- Zuletzt bearbeitet 07.10.2026 16:17:32
Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-Site Scripting. A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an authenticated user to submit content that, when later viewed by another user, executes arb...
CVE-2026-102144
- EPSS 0.36%
- Veröffentlicht 30.09.2026 20:09:53
- Zuletzt bearbeitet 07.10.2026 15:02:03
A resource exhaustion vulnerability in Kiteworks Email Protection Gateway allowed an unauthenticated remote attacker to repeatedly trigger a comparatively expensive server-side operation, causing a partial denial of service.
CVE-2026-102150
- EPSS 0.25%
- Veröffentlicht 30.09.2026 20:09:36
- Zuletzt bearbeitet 07.10.2026 13:56:02
A function in the Kiteworks Advanced Forms component was reachable without authentication. An unauthenticated attacker could potentially use it to carry out a limited set of internal service operations on the Kiteworks platform; it did not permit acc...