CVE-2026-102145
6.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
Summary
An authenticated administrator could cause the server to issue requests to, and interact with, internal network services that are not meant to be reachable through this interface. On its own this did not result in code execution.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Kiteworks | Core | 0 < 9.5.1 | affected |
| Kiteworks | Core | 9.5.1 | unaffected |
Weaknesses
- CWE-93: CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
References
- https://github.com/kiteworks/security-advisories/security/advisories/GHSA-h97r-j99c-q8xc
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.