---
id: CVE-2026-102147
title: >-
  A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an
  unauthenticated attacker to store crafted content that later executes
  arbitrary JavaScript in the authenticated session of an administrator who
  views the affec…
summary: >-
  A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an
  unauthenticated attacker to store crafted content that later executes
  arbitrary JavaScript in the authenticated session of an administrator who
  views the affec…
severity: critical
cvss: 9.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'
cwe:
  - CWE-79
vendor: Kiteworks
product: Core
affected:
  - Core < 9.5.1
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:17:03.633'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102147'
references:
  - url: >-
      https://github.com/kiteworks/security-advisories/security/advisories/GHSA-xgh2-fgj6-w93r
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T21:25:07.837Z'
---

## Overview

A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauthenticated attacker to store crafted content that later executes arbitrary JavaScript in the authenticated session of an administrator who views the affected page. This could have permitted the attacker to gain full administrative control, including the creation of a new administrative account.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
