CVE-2026-102124
A Kiteworks appliance setup interface did not enforce authentication once the appliance had completed initial configuration. An unauthenticated attacker with network access to the appliance could read and modify a limited set of setup records, including a contact name and email address captured during initial configuration.
- Published Sep 30, 2026
- CVSS 6.5 medium
- 0.2% chance of exploitation in the next 30 days (EPSS)