Description
Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection. A stored SQL injection vulnerability in a Kiteworks administrative reporting feature could allow an authenticated administrator to read sensitive data from the underlying database and to affect the availability of the service. Exploitation requires an existing, authenticated administrative account with access to the affected reporting function.
Published: 2026-09-30
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Sensitive Data Exposure
Action: Patch
AI Analysis

Impact

A stored SQL injection flaw exists in a reporting feature accessible only to authenticated administrators of Kiteworks Core. Through this vulnerability, an attacker could execute arbitrary SELECT statements against the underlying database, read confidential data, and potentially disrupt service availability. The flaw exemplifies CWE‑89 as it involves unsanitized user-supplied input that is incorporated into SQL commands.

Affected Systems

Kiteworks Core versions earlier than 9.5.0 are affected. Administrators with access to the reporting function on these releases are at risk.

Risk and Exploitability

The CVSS score of 7.2 indicates a medium‑to‑high severity with significant impact if exploited. Although EPSS data is not available, the vulnerability requires authenticated administrative access, limiting the attack surface. The flaw is not listed in CISA’s KEV catalog, suggesting it is not publicly exploited at the time of disclosure. Attackers would need to log in with administrative credentials and invoke the reporting feature; no remote unauthenticated exploitation path exists. Given the potential for data exposure and service disruption, organizations should consider this a high priority.

Generated by OpenCVE AI on September 30, 2026 at 22:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Kiteworks Core to version 9.5.0 or later.
  • If an upgrade cannot be performed immediately, disable or restrict the reporting function for administrators who do not require it.
  • Apply strict input validation and parameterized queries for all database interactions to mitigate similar SQL injection risks (CWE‑89).

Generated by OpenCVE AI on September 30, 2026 at 22:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 06:00:00 +0000

Type Values Removed Values Added
First Time appeared Kiteworks
Kiteworks core
Vendors & Products Kiteworks
Kiteworks core

Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection. A stored SQL injection vulnerability in a Kiteworks administrative reporting feature could allow an authenticated administrator to read sensitive data from the underlying database and to affect the availability of the service. Exploitation requires an existing, authenticated administrative account with access to the affected reporting function.
Title Kiteworks Core SQL Injection
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-09-30T20:05:28.045Z

Reserved: 2026-09-28T17:39:13.561Z

Link: CVE-2026-102098

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T21:16:56.500

Modified: 2026-10-01T02:17:43.350

Link: CVE-2026-102098

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T05:45:16Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')