Description
A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauthenticated attacker to store crafted content that later executes arbitrary JavaScript in the authenticated session of an administrator who views the affected page. This could have permitted the attacker to gain full administrative control, including the creation of a new administrative account.
Published: 2026-09-30
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Account Takeover via Stored XSS
Action: Immediate Patch
AI Analysis

Impact

A stored cross‑site scripting flaw in Kiteworks Core lets an unauthenticated attacker place malicious JavaScript that runs in the browser of an administrator who later views the crafted content. On execution the script gains the administrator’s session privileges, allowing the attacker to take full control of the system, create new administrative accounts, and access all protected data. This represents a full privilege escalation and compromise of the entire Kiteworks installation.

Affected Systems

The vulnerability affects the Kiteworks Core product. No version information is supplied in the advisory, so any deployment of Kiteworks Core that includes the affected content page is potentially impacted.

Risk and Exploitability

The flaw carries a CVSS score of 9.3, indicating a critical impact. The EPSS score is not available, but the lack of input validation and the ability to execute code in privileged sessions make exploitation feasible if an attacker can inject content before an administrator revisits the page. The advisory does not list the flaw in CISA’s KEV catalog, and no official workaround was provided, meaning mitigation must rely on patching or stricter controls.

Generated by OpenCVE AI on September 30, 2026 at 22:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑released patch or latest release that removes the stored XSS flaw in Kiteworks Core.
  • If a patch is unavailable, restrict or disable the page that accepts user‑generated content for non‑administrators and enforce server‑side input filtering to block script tags.
  • Implement a Content Security Policy that disallows the execution of arbitrary scripts from untrusted sources, limiting the impact of any remaining XSS payloads.

Generated by OpenCVE AI on September 30, 2026 at 22:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
First Time appeared Kiteworks
Kiteworks core
Vendors & Products Kiteworks
Kiteworks core

Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauthenticated attacker to store crafted content that later executes arbitrary JavaScript in the authenticated session of an administrator who views the affected page. This could have permitted the attacker to gain full administrative control, including the creation of a new administrative account.
Title Kiteworks Core Administrative Account Takeover through Stored Cross-site Scripting (XSS)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-09-30T20:09:08.315Z

Reserved: 2026-09-28T17:39:13.564Z

Link: CVE-2026-102147

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T21:17:03.633

Modified: 2026-10-01T02:17:43.350

Link: CVE-2026-102147

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T06:15:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')