cbcvebase.

Kiteworks Core vulnerabilities

36 known vulnerabilities affecting kiteworks/core.

Total CVEs
36
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH19MEDIUM14LOW1

Vulnerabilities

Page 1 of 2
CVE-2026-102115P2CRITICALCVSS 9.8fixed in 9.5.02026-09-30
CVE-2026-102115 [CRITICAL] CWE-640 CVE-2026-102115: Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An u Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who knew the email address of a user with a locally stored password could potentially reset that account's password without access to the emailed reset link and then authenticate as that user, including where the account ho
nvd
CVE-2026-102114P3HIGHCVSS 7.2fixed in 9.5.02026-09-30
CVE-2026-102114 [HIGH] CWE-78 CVE-2026-102114: A command injection vulnerability in Kiteworks could allow a high-privileged authenticated administr A command injection vulnerability in Kiteworks could allow a high-privileged authenticated administrator to execute arbitrary operating-system commands as root on the affected appliance node. Successful exploitation requires an administrative account with elevated privileges.
nvd
CVE-2026-102096P3HIGHCVSS 7.2fixed in 9.5.02026-09-30
CVE-2026-102096 [HIGH] CWE-78 CVE-2026-102096: Kiteworks Core before version 9.5.0 is vulnerable to OS Command Injection that allows an authenticat Kiteworks Core before version 9.5.0 is vulnerable to OS Command Injection that allows an authenticated administrator to upload a configuration package whose contents were not sufficiently validated before being processed. A crafted package could cause the underlying system to execute arbitrary operating-system commands, potentially with elevated priv
nvd
CVE-2026-102120P3HIGHCVSS 8.8fixed in 9.5.12026-09-30
CVE-2026-102120 [HIGH] CWE-78 CVE-2026-102120: A privilege escalation vulnerability in Kiteworks could have allowed an attacker who had already obt A privilege escalation vulnerability in Kiteworks could have allowed an attacker who had already obtained code execution on one node of a clustered Kiteworks deployment to run operating system commands with elevated privileges on another node of the same cluster. Insufficient input validation in an internal cluster management function let attacker-su
nvd
CVE-2026-102123P3HIGHCVSS 7.4fixed in 9.5.02026-09-30
CVE-2026-102123 [HIGH] CWE-22 CVE-2026-102123: A Kiteworks appliance setup interface did not confine a user-supplied file path to its intended dire A Kiteworks appliance setup interface did not confine a user-supplied file path to its intended directory, which could allow an unauthenticated attacker to write a file to any location writable by the affected service account, potentially compromising the integrity of the appliance or rendering it unavailable until an operator intervenes. Exploitatio
nvd
CVE-2026-102147P3CRITICALCVSS 9.3fixed in 9.5.12026-09-30
CVE-2026-102147 [CRITICAL] CWE-79 CVE-2026-102147: A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauthenticated attack A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauthenticated attacker to store crafted content that later executes arbitrary JavaScript in the authenticated session of an administrator who views the affected page. This could have permitted the attacker to gain full administrative control, including the creation of
nvd
CVE-2026-102099P3HIGHCVSS 7.2fixed in 9.5.02026-09-30
CVE-2026-102099 [HIGH] CWE-22 CVE-2026-102099: Kiteworks Core before version 9.5.0 is vulnerable to Arbitrary File Write. An improper restriction o Kiteworks Core before version 9.5.0 is vulnerable to Arbitrary File Write. An improper restriction of a user-supplied file path in a Kiteworks administrative export feature could allow an authenticated administrator to write a file to an arbitrary location on the underlying host, potentially leading to command execution on the appliance. Exploitation
nvd
CVE-2026-102125P3HIGHCVSS 8.8fixed in 9.5.02026-09-30
CVE-2026-102125 [HIGH] CWE-653 CVE-2026-102125: The sandbox that isolates document conversion on a Kiteworks appliance did not fully confine the cod The sandbox that isolates document conversion on a Kiteworks appliance did not fully confine the code running inside it. Code already executing within that sandbox could potentially escape its confinement and act with the privileges of the service account that runs the application, which could allow an attacker in that position to read or modify app
nvd
CVE-2026-102101P3HIGHCVSS 8.1fixed in 9.5.02026-09-30
CVE-2026-102101 [HIGH] CWE-502 CVE-2026-102101: Kiteworks Core before version 9.5.0 is vulnerable to Deserialization of Untrusted Data. A deserializ Kiteworks Core before version 9.5.0 is vulnerable to Deserialization of Untrusted Data. A deserialization weakness in Kiteworks Core could, under certain conditions, allow crafted data to be deserialized unsafely, potentially resulting in remote code execution on the appliance. Exploitation depends on an attacker first being able to influence the af
nvd
CVE-2026-102117P3HIGHCVSS 7.2fixed in 9.5.12026-09-30
CVE-2026-102117 [HIGH] CWE-807 CVE-2026-102117: On deployments where the remote-support capability is licensed and enabled, an authenticated System On deployments where the remote-support capability is licensed and enabled, an authenticated System Administrator who also possessed the key protecting the submitted data could redirect the underlying system's outbound support connection to a destination of their choosing. That destination could then have operating-system commands executed on the nod
nvd
CVE-2026-102113P3HIGHCVSS 7.8fixed in 9.5.02026-09-30
CVE-2026-102113 [HIGH] CWE-59 CVE-2026-102113: A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained c A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root. A privileged routine did not safely handle a filesystem path that the lower-privileged account could influence, allowing the attacker to cause a root-owned o
nvd
CVE-2026-102112P3HIGHCVSS 7.8fixed in 9.5.02026-09-30
CVE-2026-102112 [HIGH] CWE-78 CVE-2026-102112: A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained c A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root and run arbitrary commands with the highest privileges. Exploitation requires existing local access to that service account.
nvd
CVE-2026-102093P3HIGHCVSS 7.2fixed in 9.5.02026-09-30
CVE-2026-102093 [HIGH] CWE-269 CVE-2026-102093: Kiteworks Core before version 9.5.0 is vulnerable to Improper Privilege Management and does not corr Kiteworks Core before version 9.5.0 is vulnerable to Improper Privilege Management and does not correctly enforce restrictions on role assignment, which could allow an authenticated administrative user with limited, non-Sysadmin role-management permissions to elevate another user to full system-administrator privileges beyond those the administrativ
nvd
CVE-2026-102098P3HIGHCVSS 7.2fixed in 9.5.02026-09-30
CVE-2026-102098 [HIGH] CWE-89 CVE-2026-102098: Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection. A stored SQL injection vulnerabi Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection. A stored SQL injection vulnerability in a Kiteworks administrative reporting feature could allow an authenticated administrator to read sensitive data from the underlying database and to affect the availability of the service. Exploitation requires an existing, authenticated administ
nvd
CVE-2026-102129P3HIGHCVSS 7.2fixed in 9.5.12026-09-30
CVE-2026-102129 [HIGH] CWE-266 CVE-2026-102129: A user-provisioning interface in Kiteworks Core did not verify that the requesting administrator was A user-provisioning interface in Kiteworks Core did not verify that the requesting administrator was entitled to grant the role being assigned. An administrator whose delegated permissions covered role changes alone could therefore raise an account to full system-administrator privileges.
nvd
CVE-2026-102118P3HIGHCVSS 7.8fixed in 9.5.02026-09-30
CVE-2026-102118 [HIGH] CWE-59 CVE-2026-102118: A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an exist A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an existing shell under a low-privileged service account to escalate to root privileges on the appliance.
nvd
CVE-2026-102132P3HIGHCVSS 7.2fixed in 9.5.12026-09-30
CVE-2026-102132 [HIGH] CWE-284 CVE-2026-102132: An administrative import function in Kiteworks Core did not verify that the requesting administrator An administrative import function in Kiteworks Core did not verify that the requesting administrator was entitled to create the privileged integration credential being imported. A delegated administrator holding a single narrowly scoped administrative permission could therefore obtain full system administrator privileges, without any action by an ex
nvd
CVE-2026-102142P3HIGHCVSS 7.2fixed in 9.5.12026-09-30
CVE-2026-102142 [HIGH] CWE-1336 CVE-2026-102142: A system notification template on the Kiteworks appliance was rendered by a template engine that eva A system notification template on the Kiteworks appliance was rendered by a template engine that evaluated expressions contained in the stored template body. An authenticated System Administrator could potentially store a crafted template that executed operating-system commands on the appliance when the notification was next sent.
nvd
CVE-2026-102133P3MEDIUMCVSS 6.6fixed in 9.5.12026-09-30
CVE-2026-102133 [MEDIUM] CWE-77 CVE-2026-102133: An optional, separately licensed repository-connector feature in Kiteworks Core did not neutralize s An optional, separately licensed repository-connector feature in Kiteworks Core did not neutralize special characters in a user-supplied path before passing it to an external command. An authenticated system administrator could inject additional commands and write arbitrary content to files owned by the service account running the connector, enabli
nvd
CVE-2026-102100P3HIGHCVSS 8.7fixed in 9.5.02026-09-30
CVE-2026-102100 [HIGH] CWE-79 CVE-2026-102100: Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-Site Scripting. A stored cross-sit Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-Site Scripting. A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an authenticated user to submit content that, when later viewed by another user, executes arbitrary JavaScript in that user's authenticated session. This could be used to perform actions on the v
nvd
Kiteworks Core vulnerabilities | cvebase