CVE-2026-102150: Accellion Kiteworks
High severity, CVSS 7.2. EPSS: 0.2% chance of exploitation in the next 30 days.
A function in the Kiteworks Advanced Forms component was reachable without authentication. An unauthenticated attacker could potentially use it to carry out a limited set of internal service operations on the Kiteworks platform; it did not permit access to user accounts, stored files, or form submissions.
Affected products
- Accellion Kiteworks: from 9.3.0, before 9.5.1 (fixed in 9.5.1)
Published 2026-09-30. Last modified 2026-10-07.