Authentication Bypass in Appliance Setup Process by Kiteworks
CVE-2026-102110
5.9MEDIUM
What is CVE-2026-102110?
During the initial setup of Kiteworks appliances, a critical vulnerability was identified where an endpoint failed to enforce authentication requirements. This loophole allowed unauthenticated attackers to repeatedly trigger the privileged activation process. Such unauthorized actions could lead to the appliance being left in an improperly configured state, potentially disrupting the setup process. This issue is only exploitable during the initial activation phase when the appliance has not been fully configured.
Affected Version(s)
Core 0 < 9.5.1
Core 9.5.1
