---
id: CVE-2026-102090
title: Kiteworks Core before version 9.5.1 is vulnerable to Content Injection
summary: >-
  Kiteworks Core before version 9.5.1 is vulnerable to Content Injection. A URL
  parameter in the PDF viewer was insufficiently validated, allowing an
  attacker-controlled document to be loaded and displayed under the trust of the
  legitimate…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-601
vendor: Kiteworks
product: Core
affected:
  - Core < 9.5.1
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:16:55.490'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102090'
references:
  - url: >-
      https://github.com/kiteworks/security-advisories/security/advisories/GHSA-g3hj-598g-338g
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T21:25:07.819Z'
---

## Overview

Kiteworks Core before version 9.5.1 is vulnerable to Content Injection. A URL parameter in the PDF viewer was insufficiently validated, allowing an attacker-controlled document to be loaded and displayed under the trust of the legitimate application domain. This could increase the credibility of phishing attempts relying on malicious links embedded in the displayed content.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
