CVE-2026-102124Medium· 6.5▾ SunlitA Kiteworks appliance setup interface did not enforce authentication once the appliance had completed initial configuration. An unauthenticated attacker with network access to the appliance could read and modify a limited set of setup re…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A Kiteworks appliance setup interface did not enforce authentication once the appliance had completed initial configuration. An unauthenticated attacker with network access to the appliance could read and modify a limited set of setup records, including a contact name and email address captured during initial configuration.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102110Medium· 5.9An endpoint used during initial appliance setup did not require authentication and did not correctly enforce its intended state precondition, so during the initial activation window an unauthenticated network attacker could repeatedly re…
CVE-2026-102150High· 7.2A function in the Kiteworks Advanced Forms component was reachable without authentication
CVE-2026-102149Critical· 9.4Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could be assigned to
CVE-2026-102145Medium· 6.6An authenticated administrator could cause the server to issue requests to, and interact with, internal network services that are not meant to be reachable through this interface
CVE-2026-102147Critical· 9.3A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauthenticated attacker to store crafted content that later executes arbitrary JavaScript in the authenticated session of an administrator who views the affec…
CVE-2026-102144Medium· 5.3A resource exhaustion vulnerability in Kiteworks Email Protection Gateway allowed an unauthenticated remote attacker to repeatedly trigger a comparatively expensive server-side operation, causing a partial denial of service.