Kiteworks
Kiteworks Core: vulnerabilidades y CVE
Kiteworks Core tiene 17 vulnerabilidades publicadas, 17 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses17
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-102147 | Crítica (9.3) | — | — | 30 sept 2026 | A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauthenticated attacker to store crafted content that later executes arbitrary JavaScript in the authenticated session of an administrator… |
| CVE-2026-102141 | Media (6.7) | — | — | 30 sept 2026 | Two Kiteworks Core cluster-management operations did not validate file paths supplied to them, so an attacker holding root on one node of a cluster could write files as root onto another node and cause them to be… |
| CVE-2026-102134 | Media (5.4) | — | — | 30 sept 2026 | Kiteworks Core did not apply its gateway-level API security controls to every request authenticated through the platform's central authentication service. An authenticated user could reach REST API functionality over a… |
| CVE-2026-102133 | Media (6.6) | — | — | 30 sept 2026 | An optional, separately licensed repository-connector feature in Kiteworks Core did not neutralize special characters in a user-supplied path before passing it to an external command. An authenticated system… |
| CVE-2026-102132 | Alta (7.2) | — | — | 30 sept 2026 | An administrative import function in Kiteworks Core did not verify that the requesting administrator was entitled to create the privileged integration credential being imported. A delegated administrator holding a… |
| CVE-2026-102129 | Alta (7.2) | — | — | 30 sept 2026 | A user-provisioning interface in Kiteworks Core did not verify that the requesting administrator was entitled to grant the role being assigned. An administrator whose delegated permissions covered role changes alone… |
| CVE-2026-102126 | Alta (8.1) | — | — | 30 sept 2026 | A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an administrator holding only a single, narrowly scoped delegated permission to store crafted content that later executes arbitrary JavaScript… |
| CVE-2026-102115 | Crítica (9.8) | — | — | 30 sept 2026 | Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who knew the email address of a user with a locally stored password could potentially reset… |
| CVE-2026-102107 | Media (4.6) | — | — | 30 sept 2026 | Kiteworks Core contains a business logic flaw in a Kiteworks file-request feature allowed an authenticated user to send a request that appeared to originate from another user, because the server did not verify that the… |
| CVE-2026-102101 | Alta (8.1) | — | — | 30 sept 2026 | Kiteworks Core before version 9.5.0 is vulnerable to Deserialization of Untrusted Data. A deserialization weakness in Kiteworks Core could, under certain conditions, allow crafted data to be deserialized unsafely,… |
| CVE-2026-102100 | Alta (8.7) | — | — | 30 sept 2026 | Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-Site Scripting. A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an authenticated user to submit content that, when later… |
| CVE-2026-102099 | Alta (7.2) | — | — | 30 sept 2026 | Kiteworks Core before version 9.5.0 is vulnerable to Arbitrary File Write. An improper restriction of a user-supplied file path in a Kiteworks administrative export feature could allow an authenticated administrator to… |
| CVE-2026-102098 | Alta (7.2) | — | — | 30 sept 2026 | Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection. A stored SQL injection vulnerability in a Kiteworks administrative reporting feature could allow an authenticated administrator to read sensitive data… |
| CVE-2026-102096 | Alta (7.2) | — | — | 30 sept 2026 | Kiteworks Core before version 9.5.0 is vulnerable to OS Command Injection that allows an authenticated administrator to upload a configuration package whose contents were not sufficiently validated before being… |
| CVE-2026-102093 | Alta (7.2) | — | — | 30 sept 2026 | Kiteworks Core before version 9.5.0 is vulnerable to Improper Privilege Management and does not correctly enforce restrictions on role assignment, which could allow an authenticated administrative user with limited,… |
| CVE-2026-102092 | Alta (8.7) | — | — | 30 sept 2026 | Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-site Scripting (XSS) that could allow an authenticated user to store crafted content that executes arbitrary JavaScript in another user's authenticated… |
| CVE-2026-102090 | Media (4.3) | — | — | 30 sept 2026 | Kiteworks Core before version 9.5.1 is vulnerable to Content Injection. A URL parameter in the PDF viewer was insufficiently validated, allowing an attacker-controlled document to be loaded and displayed under the trust… |