Stored Cross-Site Scripting Vulnerability in Kiteworks Core Software
CVE-2026-102126
8.1HIGH
What is CVE-2026-102126?
A vulnerability in the Kiteworks Core software allows for stored cross-site scripting (XSS) attacks. This weakness enables an administrator with limited, delegated permissions to insert malicious content. When a privileged System Administrator views the affected page, the injected JavaScript executes within their session. This exploitation could lead to unauthorized escalation, allowing the lower-privileged administrator to gain full control over the tenant’s administration, including the ability to create new admin accounts.
Affected Version(s)
Core 0 < 9.5.1
Core 9.5.1
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Icare, https://yeswehack.com/hunters/icare
Supr4s, https://yeswehack.com/hunters/Supr4s
wlayzz, https://yeswehack.com/hunters/wlayzz
truff, https://yeswehack.com/hunters/truff
