---
id: CVE-2026-102100
title: >-
  Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-Site
  Scripting
summary: >-
  Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-Site
  Scripting. A stored cross-site scripting (XSS) weakness in Kiteworks Core
  could allow an authenticated user to submit content that, when later viewed by
  another user,…
severity: high
cvss: 8.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'
cwe:
  - CWE-79
vendor: Kiteworks
product: Core
affected:
  - Core < 9.5.0
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:16:56.750'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102100'
references:
  - url: >-
      https://github.com/kiteworks/security-advisories/security/advisories/GHSA-vr65-9jwc-jgjx
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T21:25:07.822Z'
---

## Overview

Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-Site Scripting. A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an authenticated user to submit content that, when later viewed by another user, executes arbitrary JavaScript in that user's authenticated session. This could be used to perform actions on the victim's behalf and may have permitted account takeover, including of higher-privileged users. Exploitation requires the victim to view the attacker-supplied content.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
