VDB
CVE-2026-102145
CVE-2026-102145
PUBLISHED
CVSS 6.6 MEDIUM
Reported by cisa-cg · Published September 30, 2026
An authenticated administrator could cause the server to issue requests to, and interact with, internal network services that are not meant to be reachable through this interface. On its own this did not result in code execution.
Risk Scores
CVSS 3.1
6.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kiteworks | Core | 0, 9.5.1 |
| Kiteworks | Core | 0, 9.5.1, 0 |
Timeline
- Sep 30, 2026 CVE Published
- Oct 1, 2026 EPSS Score
- Oct 1, 2026 CVE Updated
- Oct 2, 2026 EPSS Score
- Oct 6, 2026 EPSS Score