Impact
The vulnerability allows an authenticated administrator who has the optional licensed gateway role enabled to supply an arbitrary connector URL. The server retrieves the URL without validating its scheme or destination, leading to a server‑side request forgery that can target services on the internal network. Because the flaw exposes internal assets, an attacker with administrative privileges could discover, access, or manipulate those services, potentially leaking sensitive data or facilitating further privilege escalation. The weakness is identified as CWE‑918.
Affected Systems
The issue affects Kiteworks Core servers that have the licensed gateway role enabled. No specific version range is provided, so all installations of Kiteworks Core with an active gateway role are potentially susceptible unless otherwise mitigated by configuration changes.
Risk and Exploitability
The CVSS score of 3.3 indicates a low overall severity, and no EPSS score is available, suggesting limited exploitation activity to date. The vendor has not listed it in the CISA KEV catalog. The attack vector is likely through the authenticated administrative interface used to configure the connector URL; successful exploitation requires the gateway role to be active, meaning only privileged administrators can execute it. While the risk to external attackers is low, insiders or compromised admin accounts pose a substantive threat to internal network integrity.
OpenCVE Enrichment