Description
An authenticated administrator on a node with an optional, separately licensed gateway role enabled could supply a connector URL that the server retrieved without sufficient validation of its scheme or destination, causing the server to issue requests to internal network services. Exploitation requires the licensed gateway role to be active.
Published: 2026-09-30
Score: 3.3 Low
EPSS: n/a
KEV: No
Impact: Server Side Request Forgery enabling internal network access
Action: Assess Impact
AI Analysis

Impact

The vulnerability allows an authenticated administrator who has the optional licensed gateway role enabled to supply an arbitrary connector URL. The server retrieves the URL without validating its scheme or destination, leading to a server‑side request forgery that can target services on the internal network. Because the flaw exposes internal assets, an attacker with administrative privileges could discover, access, or manipulate those services, potentially leaking sensitive data or facilitating further privilege escalation. The weakness is identified as CWE‑918.

Affected Systems

The issue affects Kiteworks Core servers that have the licensed gateway role enabled. No specific version range is provided, so all installations of Kiteworks Core with an active gateway role are potentially susceptible unless otherwise mitigated by configuration changes.

Risk and Exploitability

The CVSS score of 3.3 indicates a low overall severity, and no EPSS score is available, suggesting limited exploitation activity to date. The vendor has not listed it in the CISA KEV catalog. The attack vector is likely through the authenticated administrative interface used to configure the connector URL; successful exploitation requires the gateway role to be active, meaning only privileged administrators can execute it. While the risk to external attackers is low, insiders or compromised admin accounts pose a substantive threat to internal network integrity.

Generated by OpenCVE AI on September 30, 2026 at 22:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Disable the optional licensed gateway role when it is not required, limiting the attack surface for SSRF.
  • Apply any available Kiteworks Core patch or upgrade from the vendor that addresses this SSRF flaw as soon as it is released.
  • Configure the gateway to enforce a strict whitelist of outbound URLs or apply firewall rules that block internal network requests from the server to protect against accidental or malicious internal traffic.

Generated by OpenCVE AI on September 30, 2026 at 22:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Kiteworks
Kiteworks core
Vendors & Products Kiteworks
Kiteworks core

Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description An authenticated administrator on a node with an optional, separately licensed gateway role enabled could supply a connector URL that the server retrieved without sufficient validation of its scheme or destination, causing the server to issue requests to internal network services. Exploitation requires the licensed gateway role to be active.
Title Kiteworks Core Server-Side Request Forgery (SSRF)
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-09-30T20:11:32.172Z

Reserved: 2026-09-28T17:39:13.564Z

Link: CVE-2026-102138

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T21:17:02.543

Modified: 2026-10-01T02:17:43.350

Link: CVE-2026-102138

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T06:00:13Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)