Description
An endpoint used during initial appliance setup did not require authentication and did not correctly enforce its intended state precondition, so during the initial activation window an unauthenticated network attacker could repeatedly re-trigger the privileged activation process. This could disrupt setup and leave the appliance in an incompletely configured state. The issue is only reachable while an appliance is being activated for the first time and not yet fully configured.
Published: 2026-09-30
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service during initial appliance setup
Action: Patch
AI Analysis

Impact

The vulnerability exists in an endpoint used only during the very first activation of a Kiteworks appliance. Because the endpoint performs no authentication verification and fails to enforce the expected precondition state, an unauthenticated attacker could repeatedly trigger the privileged activation process. This leads to an incomplete or unstable appliance configuration, effectively disrupting setup and causing denial of service to legitimate administrators.

Affected Systems

The affected vendor is Kiteworks, specifically the Core appliance. Product versions are not listed in the advisory, but the flaw applies to any instance undergoing initial activation for the first time and not yet fully configured.

Risk and Exploitability

The CVSS score of 5.9 places the issue in the moderate severity band. No EPSS figure is provided, and the vulnerability is not currently catalogued in CISA KEV. The attack can only occur while the appliance is in its activation window, but an attacker who can reach the network exposed setup endpoint can repeatedly invoke the vulnerable process. The limited scope of exposure reduces the overall risk, yet the ability to disrupt the entire setup process justifies an urgent patch.

Generated by OpenCVE AI on September 30, 2026 at 22:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install vendor‑issued patch or upgrade to a release that enforces authentication on the activation endpoint
  • Restrict external network access to the setup endpoint until the appliance is fully configured, using firewalls or segmentation
  • Monitor log and network traffic during the activation window for repeated unauthenticated activation attempts and investigate any anomalies

Generated by OpenCVE AI on September 30, 2026 at 22:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description An endpoint used during initial appliance setup did not require authentication and did not correctly enforce its intended state precondition, so during the initial activation window an unauthenticated network attacker could repeatedly re-trigger the privileged activation process. This could disrupt setup and leave the appliance in an incompletely configured state. The issue is only reachable while an appliance is being activated for the first time and not yet fully configured.
Title Missing authentication on a Kiteworks appliance setup function
Weaknesses CWE-306
CWE-670
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-09-30T20:21:42.338Z

Reserved: 2026-09-28T17:39:13.562Z

Link: CVE-2026-102110

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T21:16:57.990

Modified: 2026-09-30T21:16:57.990

Link: CVE-2026-102110

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T22:30:07Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function

  • CWE-670

    Always-Incorrect Control Flow Implementation