VDB

CVE-2026-102111

CVE-2026-102111 PUBLISHED CVSS 4.9 MEDIUM

Reported by cisa-cg · Published September 30, 2026

Kiteworks did not enforce the maximum permitted value for a configurable security-policy setting. An authenticated administrator could set this value outside its intended range so that the associated control never activated, while the control continued to appear enabled in the administrative interface and audit log, allowing it to be silently rendered ineffective.

Risk Scores

CVSS 3.1
4.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

Affected Products

VendorProductVersions
KiteworksCore0, 9.5.0
KiteworksCore0, 9.5.0, 0

Timeline

  • Sep 30, 2026 Coalition ESS Score
  • Sep 30, 2026 CVE Published
  • Oct 1, 2026 EPSS Score
  • Oct 2, 2026 EPSS Score
  • Oct 7, 2026 EPSS Score
  • Oct 7, 2026 CVE Updated

References

  • url vendor-advisory
  • url third-party-advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›