Path Traversal Vulnerability in Kiteworks Appliance Setup Interface
CVE-2026-102123

7.4HIGH

Key Information:

Vendor

Kiteworks

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-102123?

The Kiteworks appliance features a setup interface that fails to restrict user-supplied file paths to designated directories. This flaw could permit an unauthenticated attacker to manipulate file paths, enabling them to write files to any location that the service account is allowed to access. Such exploitation could lead to compromised appliance integrity or make the appliance unavailable until an administrative intervention is performed. Accessing the vulnerable interface typically requires network access that may be available during the initial provisioning of the appliance or due to custom configurations that deviate from the standard security setup.

Affected Version(s)

Core 0 < 9.5.0

Core 9.5.0

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Icare, https://yeswehack.com/hunters/icare
Supr4s, https://yeswehack.com/hunters/Supr4s
wlayzz, https://yeswehack.com/hunters/wlayzz
truff, https://yeswehack.com/hunters/truff
.