File Upload Vulnerability in Kiteworks Appliances
CVE-2026-102137

4.1MEDIUM

Key Information:

Vendor

Kiteworks

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-102137?

An authenticated administrator on Kiteworks appliances can bypass essential content validation during the administrative file upload process. This vulnerability allows the upload of files that may contain dangerous content. While this vulnerability does not directly lead to code execution, it creates an opportunity for further exploitation if coupled with another security flaw.

Affected Version(s)

Core 0 < 9.5.1

Core 9.5.1

References

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.