---
id: CVE-2026-102098
title: Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection
summary: >-
  Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection. A stored
  SQL injection vulnerability in a Kiteworks administrative reporting feature
  could allow an authenticated administrator to read sensitive data from the
  underlyin…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-89
vendor: Kiteworks
product: Core
affected:
  - Core < 9.5.0
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:16:56.500'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102098'
references:
  - url: >-
      https://github.com/kiteworks/security-advisories/security/advisories/GHSA-cqg3-857q-cqj6
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T21:25:07.822Z'
---

## Overview

Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection. A stored SQL injection vulnerability in a Kiteworks administrative reporting feature could allow an authenticated administrator to read sensitive data from the underlying database and to affect the availability of the service. Exploitation requires an existing, authenticated administrative account with access to the affected reporting function.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
