Remote Code Execution Vulnerability in Kiteworks Gateway by Kiteworks
CVE-2026-102138
3.3LOW
What is CVE-2026-102138?
An authenticated administrator with an active licensed gateway role on a Kiteworks node can exploit a vulnerability by providing a connector URL. The server retrieves this URL without adequate validation of its scheme or destination, potentially leading to unauthorized requests to internal network services. This vulnerability emphasizes the critical importance of input validation and securing administrative functionalities within a network environment.
Affected Version(s)
Core 0 < 9.5.1
Core 9.5.1
References
CVSS V3.1
Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Icare, https://yeswehack.com/hunters/icare
Supr4s, https://yeswehack.com/hunters/Supr4s
wlayzz, https://yeswehack.com/hunters/wlayzz
truff, https://yeswehack.com/hunters/truff
