Description
A Kiteworks appliance setup interface did not enforce authentication once the appliance had completed initial configuration. An unauthenticated attacker with network access to the appliance could read and modify a limited set of setup records, including a contact name and email address captured during initial configuration.
Published: 2026-09-30
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Unauthenticated Configuration Access
Action: Assess Impact
AI Analysis

Impact

A configuration interface in the Kiteworks appliance does not enforce authentication once initial setup is finished. An attacker who can reach the appliance over the network can read and modify a limited number of configuration entries—including the contact name and email address collected during the first configuration. This flaw allows an unauthenticated user to alter critical settings, potentially extending their reach into the system or facilitating further compromise.

Affected Systems

Kiteworks Core products are affected. The vulnerability applies to all versions of the appliance that expose the post‑initial‑configuration setup interface.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity vulnerability. EPSS information is unavailable and the vulnerability is not listed in CISA’s KEV catalog, suggesting no widely known exploits yet. The attack requires network access to the appliance and no authentication, making it straightforward for an attacker with connectivity to the device to exploit the flaw by reading or changing setup records.

Generated by OpenCVE AI on September 30, 2026 at 21:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Review Kiteworks security advisories and apply any available update that adds authentication to the post‑setup interface.
  • Restrict network reach to the setup interface by using firewall rules or subnet segmentation so that only trusted administrators can access it.
  • If no fix exists, enforce additional access controls such as network segmentation, VPN access, or disabling the setup interface until a patch is released.

Generated by OpenCVE AI on September 30, 2026 at 21:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
First Time appeared Kiteworks
Kiteworks core
Vendors & Products Kiteworks
Kiteworks core

Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A Kiteworks appliance setup interface did not enforce authentication once the appliance had completed initial configuration. An unauthenticated attacker with network access to the appliance could read and modify a limited set of setup records, including a contact name and email address captured during initial configuration.
Title Kiteworks Core Missing Authentication for Critical Function
Weaknesses CWE-306
CWE-670
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-09-30T20:15:38.627Z

Reserved: 2026-09-28T17:39:13.563Z

Link: CVE-2026-102124

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T21:17:00.677

Modified: 2026-10-01T02:17:43.350

Link: CVE-2026-102124

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T05:30:17Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function

  • CWE-670

    Always-Incorrect Control Flow Implementation