{"id":"CVE-2026-102140","title":"An authenticated administrator could initiate an administrative import using a file whose contents were not fully verified, because the import validated only the file's header rather than the complete file","summary":"An authenticated administrator could initiate an administrative import using a file whose contents were not fully verified, because the import validated only the file's header rather than the complete file. This could allow unverified or…","severity":"medium","cvss":4.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N","cwe":["CWE-345"],"vendor":"Kiteworks","product":"Core","affected":["Core < 9.5.1"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T21:17:02.783","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-102140","references":[{"url":"https://github.com/kiteworks/security-advisories/security/advisories/GHSA-wfxj-p5jc-jqjw","label":"9119a7d8-5eab-497f-8521-727c672e3725"},{"url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json","label":"9119a7d8-5eab-497f-8521-727c672e3725"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-30T21:25:07.835Z","slug":"CVE-2026-102140","body":"## Overview\n\nAn authenticated administrator could initiate an administrative import using a file whose contents were not fully verified, because the import validated only the file's header rather than the complete file. This could allow unverified or forged content to be accepted and processed, affecting the integrity of the imported data.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":27,"depthScoreParts":{"impact":27,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}