---
id: CVE-2026-102092
title: >-
  Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-site
  Scripting (XSS) that could allow an authenticated user to store crafted
  content that executes arbitrary JavaScript in another user's authenticated
  session when they p…
summary: >-
  Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-site
  Scripting (XSS) that could allow an authenticated user to store crafted
  content that executes arbitrary JavaScript in another user's authenticated
  session when they p…
severity: high
cvss: 8.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'
cwe:
  - CWE-79
vendor: Kiteworks
product: Core
affected:
  - Core < 9.5.0
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:16:55.743'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102092'
references:
  - url: >-
      https://github.com/kiteworks/security-advisories/security/advisories/GHSA-mhw9-vrqq-m434
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T21:25:07.820Z'
---

## Overview

Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-site Scripting (XSS) that could allow an authenticated user to store crafted content that executes arbitrary JavaScript in another user's authenticated session when they preview shared content. This could potentially lead to session compromise and account takeover.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
