CVE-2026-102140
4.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Summary
An authenticated administrator could initiate an administrative import using a file whose contents were not fully verified, because the import validated only the file's header rather than the complete file. This could allow unverified or forged content to be accepted and processed, affecting the integrity of the imported data.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Kiteworks | Core | 0 < 9.5.1 | affected |
| Kiteworks | Core | 9.5.1 | unaffected |
Weaknesses
- CWE-345: CWE-345 Insufficient Verification of Data Authenticity
References
- https://github.com/kiteworks/security-advisories/security/advisories/GHSA-wfxj-p5jc-jqjw
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.