Description
Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-Site Scripting. A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an authenticated user to submit content that, when later viewed by another user, executes arbitrary JavaScript in that user's authenticated session. This could be used to perform actions on the victim's behalf and may have permitted account takeover, including of higher-privileged users. Exploitation requires the victim to view the attacker-supplied content.
Published: 2026-09-30
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting (XSS)
Action: Apply Patch
AI Analysis

Impact

A stored cross‑site scripting weakness allows an authenticated user to submit malicious content that, when viewable by another authenticated user, runs arbitrary JavaScript within that user's session. This can lead to actions performed on behalf of the victim and potentially result in the compromise of higher‑privileged accounts. The flaw is an example of improper handling of user input and output in the application layer.

Affected Systems

The vulnerability is present in Kiteworks Core versions prior to 9.5.0; any instance of the product running an affected version is at risk.

Risk and Exploitability

With a CVSS score of 8.7, the flaw is considered high severity. Although the EPSS score is not listed, the vulnerability is exploitable by any authenticated user who can post content and by victims who subsequently view that content. The impact is limited to accounts that view the injected data, but the potential for account takeover of higher‑privileged users raises the overall risk. The vulnerability is not currently listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 30, 2026 at 22:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Kiteworks Core to version 9.5.0 or newer to fix the stored XSS flaw.
  • If an upgrade is not immediately feasible, enforce strict output encoding or sanitization on all user‑supplied fields that can contain scriptable content.
  • Review and limit user roles so that only trusted accounts can create or modify content that is rendered as HTML to reduce the attack surface.

Generated by OpenCVE AI on September 30, 2026 at 22:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 06:00:00 +0000

Type Values Removed Values Added
First Time appeared Kiteworks
Kiteworks core
Vendors & Products Kiteworks
Kiteworks core

Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-Site Scripting. A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an authenticated user to submit content that, when later viewed by another user, executes arbitrary JavaScript in that user's authenticated session. This could be used to perform actions on the victim's behalf and may have permitted account takeover, including of higher-privileged users. Exploitation requires the victim to view the attacker-supplied content.
Title Kiteworks Core stored XSS
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-09-30T20:10:05.276Z

Reserved: 2026-09-28T17:39:13.561Z

Link: CVE-2026-102100

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T21:16:56.750

Modified: 2026-10-01T02:17:43.350

Link: CVE-2026-102100

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T05:45:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')