CVE-2026-102147Critical· 9.3▾ MidnightA stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauthenticated attacker to store crafted content that later executes arbitrary JavaScript in the authenticated session of an administrator who views the affec…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 51.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauthenticated attacker to store crafted content that later executes arbitrary JavaScript in the authenticated session of an administrator who views the affected page. This could have permitted the attacker to gain full administrative control, including the creation of a new administrative account.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102126High· 8.1A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an administrator holding only a single, narrowly scoped delegated permission to store crafted content that later executes arbitrary JavaScript in the authenticate…
CVE-2026-102100High· 8.7Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-Site Scripting
CVE-2026-102092High· 8.7Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-site Scripting (XSS) that could allow an authenticated user to store crafted content that executes arbitrary JavaScript in another user's authenticated session when they p…
CVE-2026-102145Medium· 6.6An authenticated administrator could cause the server to issue requests to, and interact with, internal network services that are not meant to be reachable through this interface
CVE-2026-102141Medium· 6.7Two Kiteworks Core cluster-management operations did not validate file paths supplied to them, so an attacker holding root on one node of a cluster could write files as root onto another node and cause them to be executed there
CVE-2026-102142High· 7.2A system notification template on the Kiteworks appliance was rendered by a template engine that evaluated expressions contained in the stored template body