cbcvebase.
CVE-2026-102140
published 2026-09-30

CVE-2026-102140: An authenticated administrator could initiate an administrative import using a file whose contents were not fully verified, because the import validated only…

PriorityP427medium4.9CVSS 3.1
AVNACLPRHUINSUCNIHAN
EPSS
0.14%
2.8th percentile
An authenticated administrator could initiate an administrative import using a file whose contents were not fully verified, because the import validated only the file's header rather than the complete file. This could allow unverified or forged content to be accepted and processed, affecting the integrity of the imported data.

Affected

1 ranges
VendorProductVersion rangeFixed in
kiteworkscore< 9.5.19.5.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.