CVE-2026-102145: Kiteworks Core

Medium severity, CVSS 6.6. EPSS: 0.3% chance of exploitation in the next 30 days.

An authenticated administrator could cause the server to issue requests to, and interact with, internal network services that are not meant to be reachable through this interface. On its own this did not result in code execution.

Affected products

  • Kiteworks Core: before 9.5.1 (fixed in 9.5.1)

Published 2026-09-30. Last modified 2026-10-01.