Description
Kiteworks Core before version 9.5.1 is vulnerable to Content Injection. A URL parameter in the PDF viewer was insufficiently validated, allowing an attacker-controlled document to be loaded and displayed under the trust of the legitimate application domain. This could increase the credibility of phishing attempts relying on malicious links embedded in the displayed content.
Published: 2026-09-30
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Content Injection leading to potential trust amplification for phishing
Action: Apply Patch
AI Analysis

Impact

Kiteworks Core prior to 9.5.1 contains a content injection vulnerability in its PDF viewer. A URL parameter controlling the document source is insufficiently validated, permitting a maliciously crafted link to load a remote document under the same origin as the legitimate application. The result is that attackers can embed malicious links within the displayed content, increasing the credibility of phishing attacks. The CWE identifier for this weakness is 601, which denotes improper validation of user supplied data used for authority decisions.

Affected Systems

All installations of Kiteworks Core running versions older than 9.5.1 are affected. The problem arises wherever the PDF viewer component accepts any URL without verifying that it points to an internal, trusted source.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate risk level. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, as an attacker can influence the victim via a malicious link that opens the PDF viewer. Exploitation requires the victim to open the infected document; no elevated privileges are necessary. Because the vulnerability increases the credibility of phishing attempts, its impact is primarily on user trust and potential credential compromise rather than direct system compromise.

Generated by OpenCVE AI on September 30, 2026 at 22:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Kiteworks Core to version 9.5.1 or later.
  • Restrict the PDF viewer to allow only internally generated URLs and deny external or user-specified document sources.
  • Implement strict input validation or a whitelist for the viewer’s URL parameter to ensure only trusted domains are permitted, following the guidance for CWE‑601 vulnerabilities.

Generated by OpenCVE AI on September 30, 2026 at 22:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Kiteworks
Kiteworks core
Vendors & Products Kiteworks
Kiteworks core

Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description Kiteworks Core before version 9.5.1 is vulnerable to Content Injection. A URL parameter in the PDF viewer was insufficiently validated, allowing an attacker-controlled document to be loaded and displayed under the trust of the legitimate application domain. This could increase the credibility of phishing attempts relying on malicious links embedded in the displayed content.
Title Kiteworks Core content injection
Weaknesses CWE-601
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-09-30T20:05:32.183Z

Reserved: 2026-09-28T17:39:13.560Z

Link: CVE-2026-102090

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T21:16:55.490

Modified: 2026-10-01T02:17:43.350

Link: CVE-2026-102090

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T05:00:12Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')