---
id: CVE-2026-102140
title: >-
  An authenticated administrator could initiate an administrative import using a
  file whose contents were not fully verified, because the import validated only
  the file's header rather than the complete file
summary: >-
  An authenticated administrator could initiate an administrative import using a
  file whose contents were not fully verified, because the import validated only
  the file's header rather than the complete file. This could allow unverified
  or…
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-345
vendor: Kiteworks
product: Core
affected:
  - Core < 9.5.1
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:17:02.783'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102140'
references:
  - url: >-
      https://github.com/kiteworks/security-advisories/security/advisories/GHSA-wfxj-p5jc-jqjw
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T21:25:07.835Z'
---

## Overview

An authenticated administrator could initiate an administrative import using a file whose contents were not fully verified, because the import validated only the file's header rather than the complete file. This could allow unverified or forged content to be accepted and processed, affecting the integrity of the imported data.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
