---
id: CVE-2026-102138
title: >-
  An authenticated administrator on a node with an optional, separately licensed
  gateway role enabled could supply a connector URL that the server retrieved
  without sufficient validation of its scheme or destination, causing the server
  to …
summary: >-
  An authenticated administrator on a node with an optional, separately licensed
  gateway role enabled could supply a connector URL that the server retrieved
  without sufficient validation of its scheme or destination, causing the server
  to …
severity: low
cvss: 3.3
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-918
vendor: Kiteworks
product: Core
affected:
  - Core < 9.5.1
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:17:02.543'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102138'
references:
  - url: >-
      https://github.com/kiteworks/security-advisories/security/advisories/GHSA-q9w9-c5hj-87jm
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T21:25:07.835Z'
---

## Overview

An authenticated administrator on a node with an optional, separately licensed gateway role enabled could supply a connector URL that the server retrieved without sufficient validation of its scheme or destination, causing the server to issue requests to internal network services. Exploitation requires the licensed gateway role to be active.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
