---
id: CVE-2026-102145
title: >-
  An authenticated administrator could cause the server to issue requests to,
  and interact with, internal network services that are not meant to be
  reachable through this interface
summary: >-
  An authenticated administrator could cause the server to issue requests to,
  and interact with, internal network services that are not meant to be
  reachable through this interface. On its own this did not result in code
  execution.
severity: medium
cvss: 6.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L'
cwe:
  - CWE-93
vendor: Kiteworks
product: Core
affected:
  - Core < 9.5.1
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:17:03.390'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102145'
references:
  - url: >-
      https://github.com/kiteworks/security-advisories/security/advisories/GHSA-h97r-j99c-q8xc
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T21:25:07.837Z'
---

## Overview

An authenticated administrator could cause the server to issue requests to, and interact with, internal network services that are not meant to be reachable through this interface. On its own this did not result in code execution.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
