VDB
CVE-2026-102140
CVE-2026-102140
PUBLISHED
CVSS 4.9 MEDIUM
Reported by cisa-cg · Published September 30, 2026
An authenticated administrator could initiate an administrative import using a file whose contents were not fully verified, because the import validated only the file's header rather than the complete file. This could allow unverified or forged content to be accepted and processed, affecting the integrity of the imported data.
Risk Scores
CVSS 3.1
4.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kiteworks | Core | 0, 9.5.1 |
| Kiteworks | Core | 0, 9.5.1, 0 |
Timeline
- Sep 30, 2026 CVE Published
- Oct 1, 2026 EPSS Score
- Oct 1, 2026 CVE Updated
- Oct 2, 2026 EPSS Score