cbcvebase.
CVE-2026-102111
published 2026-09-30

CVE-2026-102111: Kiteworks did not enforce the maximum permitted value for a configurable security-policy setting. An authenticated administrator could set this value outside…

PriorityP428medium4.9CVSS 3.1
AVNACLPRHUINSUCNIHAN
EPSS
0.21%
10.5th percentile
Kiteworks did not enforce the maximum permitted value for a configurable security-policy setting. An authenticated administrator could set this value outside its intended range so that the associated control never activated, while the control continued to appear enabled in the administrative interface and audit log, allowing it to be silently rendered ineffective.

Affected

1 ranges
VendorProductVersion rangeFixed in
kiteworkscore< 9.5.09.5.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.