---
id: CVE-2026-102110
title: >-
  An endpoint used during initial appliance setup did not require authentication
  and did not correctly enforce its intended state precondition, so during the
  initial activation window an unauthenticated network attacker could repeatedly
  re…
summary: >-
  An endpoint used during initial appliance setup did not require authentication
  and did not correctly enforce its intended state precondition, so during the
  initial activation window an unauthenticated network attacker could repeatedly
  re…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-306
  - CWE-670
vendor: Kiteworks
product: Core
affected:
  - Core < 9.5.1
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:16:57.990'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102110'
references:
  - url: >-
      https://github.com/kiteworks/security-advisories/security/advisories/GHSA-qfqh-c638-m5pg
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T21:25:07.826Z'
---

## Overview

An endpoint used during initial appliance setup did not require authentication and did not correctly enforce its intended state precondition, so during the initial activation window an unauthenticated network attacker could repeatedly re-trigger the privileged activation process. This could disrupt setup and leave the appliance in an incompletely configured state. The issue is only reachable while an appliance is being activated for the first time and not yet fully configured.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
