cbcvebase.
CVE-2026-102147
published 2026-09-30

CVE-2026-102147: A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauthenticated attacker to store crafted content that later executes arbitrary…

PriorityP350critical9.3CVSS 3.1
AVNACLPRNUIRSCCHIHAN
EPSS
0.29%
20.2th percentile
A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauthenticated attacker to store crafted content that later executes arbitrary JavaScript in the authenticated session of an administrator who views the affected page. This could have permitted the attacker to gain full administrative control, including the creation of a new administrative account.

Affected

1 ranges
VendorProductVersion rangeFixed in
kiteworkscore< 9.5.19.5.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.