Description
An authenticated administrator could cause the server to issue requests to, and interact with, internal network services that are not meant to be reachable through this interface. On its own this did not result in code execution.
Published: 2026-09-30
Score: 6.6 Medium
EPSS: n/a
KEV: No
Impact: Server‑Side Request Forgery
Action: Apply Patch
AI Analysis

Impact

An authenticated administrator can manipulate the server to issue requests to internal network services that are not exposed through the normal interface, enabling the discovery or interaction with resources that should remain unreachable. This vulnerability is a server‑side request forgery (SSRF) caused by CRLF injection (CWE‑93) and does not, on its own, execute code on the Kiteworks Core server, but it does expose internal services and creates a potential foothold for further attacks.

Affected Systems

Kiteworks Core is the only affected product; version information is not provided in the advisory. Review the vendor’s security notice for details on which releases require the patch.

Risk and Exploitability

The CVSS score of 6.6 indicates moderate severity. Because the attack requires authenticated administrator privileges, the exploitability is limited to accounts with such rights, but the lack of code execution does not eliminate the risk of data exposure or lateral movement. The EPSS score is not available, and the issue is not listed in any KEV catalog.

Generated by OpenCVE AI on September 30, 2026 at 22:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Kiteworks Core patch that resolves the CRLF injection SSRF vulnerability.
  • Restrict administrator access and enforce strong authentication to limit the attacker’s ability to trigger the vulnerability.
  • Implement network segmentation or firewall rules to block unintended internal service requests originating from the Kiteworks server.

Generated by OpenCVE AI on September 30, 2026 at 22:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
First Time appeared Kiteworks
Kiteworks core
Vendors & Products Kiteworks
Kiteworks core

Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description An authenticated administrator could cause the server to issue requests to, and interact with, internal network services that are not meant to be reachable through this interface. On its own this did not result in code execution.
Title Kiteworks Core Server-Side Request Forgery through CRLF Injection
Weaknesses CWE-93
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-09-30T20:08:34.493Z

Reserved: 2026-09-28T17:39:13.564Z

Link: CVE-2026-102145

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T21:17:03.390

Modified: 2026-10-01T02:17:43.350

Link: CVE-2026-102145

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T06:15:14Z

Weaknesses
  • CWE-93

    Improper Neutralization of CRLF Sequences ('CRLF Injection')