Kiteworks Core
35 known vulnerabilities in Kiteworks Core, 2 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-102147 CVSS 9.3 critical A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauthenticated attacker to store crafted content that later…
- CVE-2026-102145 CVSS 6.6 medium An authenticated administrator could cause the server to issue requests to, and interact with, internal network services that are not…
- CVE-2026-102142 CVSS 7.2 high A system notification template on the Kiteworks appliance was rendered by a template engine that evaluated expressions contained in the…
- CVE-2026-102141 CVSS 6.7 medium Two Kiteworks Core cluster-management operations did not validate file paths supplied to them, so an attacker holding root on one node of…
- CVE-2026-102140 CVSS 4.9 medium An authenticated administrator could initiate an administrative import using a file whose contents were not fully verified, because the…
- CVE-2026-102138 CVSS 3.3 low An authenticated administrator on a node with an optional, separately licensed gateway role enabled could supply a connector URL that the…
- CVE-2026-102137 CVSS 4.1 medium An authenticated administrator could bypass the content validation applied to an administrative file upload and store a file containing…
- CVE-2026-102136 CVSS 6.3 medium In multi-node deployments, an attacker who had already obtained code execution on one appliance node could submit a value through an…
- CVE-2026-102134 CVSS 5.4 medium Kiteworks Core did not apply its gateway-level API security controls to every request authenticated through the platform's central…
- CVE-2026-102133 CVSS 6.6 medium An optional, separately licensed repository-connector feature in Kiteworks Core did not neutralize special characters in a user-supplied…
- CVE-2026-102132 CVSS 7.2 high An administrative import function in Kiteworks Core did not verify that the requesting administrator was entitled to create the privileged…
- CVE-2026-102129 CVSS 7.2 high A user-provisioning interface in Kiteworks Core did not verify that the requesting administrator was entitled to grant the role being…
- CVE-2026-102126 CVSS 8.1 high A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an administrator holding only a single, narrowly scoped…
- CVE-2026-102125 CVSS 8.8 high The sandbox that isolates document conversion on a Kiteworks appliance did not fully confine the code running inside it. Code already…
- CVE-2026-102124 CVSS 6.5 medium A Kiteworks appliance setup interface did not enforce authentication once the appliance had completed initial configuration. An…
- CVE-2026-102123 CVSS 7.4 high A Kiteworks appliance setup interface did not confine a user-supplied file path to its intended directory, which could allow an…
- CVE-2026-102122 CVSS 4.3 medium Kiteworks did not correctly enforce which roles a shared folder's manager was permitted to assign. In a default configuration, an…
- CVE-2026-102120 CVSS 8.8 high A privilege escalation vulnerability in Kiteworks could have allowed an attacker who had already obtained code execution on one node of a…
- CVE-2026-102118 CVSS 7.8 high A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an existing shell under a low-privileged…
- CVE-2026-102117 CVSS 7.2 high On deployments where the remote-support capability is licensed and enabled, an authenticated System Administrator who also possessed the…
- CVE-2026-102115 CVSS 9.8 critical Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who knew the…
- CVE-2026-102114 CVSS 7.2 high A command injection vulnerability in Kiteworks could allow a high-privileged authenticated administrator to execute arbitrary…
- CVE-2026-102113 CVSS 7.8 high A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged…
- CVE-2026-102112 CVSS 7.8 high A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged…
- CVE-2026-102111 CVSS 4.9 medium Kiteworks did not enforce the maximum permitted value for a configurable security-policy setting. An authenticated administrator could set…
- CVE-2026-102110 CVSS 5.9 medium An endpoint used during initial appliance setup did not require authentication and did not correctly enforce its intended state…
- CVE-2026-102107 CVSS 4.6 medium Kiteworks Core contains a business logic flaw in a Kiteworks file-request feature allowed an authenticated user to send a request that…
- CVE-2026-102101 CVSS 8.1 high Kiteworks Core before version 9.5.0 is vulnerable to Deserialization of Untrusted Data. A deserialization weakness in Kiteworks Core…
- CVE-2026-102100 CVSS 8.7 high Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-Site Scripting. A stored cross-site scripting (XSS) weakness in…
- CVE-2026-102099 CVSS 7.2 high Kiteworks Core before version 9.5.0 is vulnerable to Arbitrary File Write. An improper restriction of a user-supplied file path in a…