CVE-2026-102124

Summary

A Kiteworks appliance setup interface did not enforce authentication once the appliance had completed initial configuration. An unauthenticated attacker with network access to the appliance could read and modify a limited set of setup records, including a contact name and email address captured during initial configuration.

Affected Software

VendorProductVersion RangeStatus
KiteworksCore0 < 9.5.0affected
KiteworksCore9.5.0unaffected

Weaknesses

  • CWE-306: CWE-306 Missing Authentication for Critical Function
  • CWE-670: CWE-670 Always-Incorrect Control Flow Implementation

References