Security Weakness in Kiteworks Affecting Configuration Control
CVE-2026-102111

4.9MEDIUM

Key Information:

Vendor

Kiteworks

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-102111?

Kiteworks has a security flaw that allows an authenticated administrator to set a configurable security-policy setting beyond its intended limits. This misconfiguration renders the associated control ineffective, even though it appears enabled in the administrative interface and audit log. As a result, critical security measures may not function as intended, increasing the risk of potential security breaches.

Affected Version(s)

Core 0 < 9.5.0

Core 9.5.0

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.