CVE-2026-102145

Summary

An authenticated administrator could cause the server to issue requests to, and interact with, internal network services that are not meant to be reachable through this interface. On its own this did not result in code execution.

Affected Software

VendorProductVersion RangeStatus
KiteworksCore0 < 9.5.1affected
KiteworksCore9.5.1unaffected

Weaknesses

  • CWE-93: CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')

References