CVE-2026-102150
A function in the Kiteworks Advanced Forms component was reachable without authentication. An unauthenticated attacker could potentially use it to carry out a limited set of internal service operations on the Kiteworks platform; it did not permit access to user accounts, stored files, or form submissions.
- Published Sep 30, 2026
- CVSS 7.2 high
- 0.2% chance of exploitation in the next 30 days (EPSS)