PT-2026-103528 · Kiteworks · Kiteworks Core
CVE-2026-102090
·
Published
2026-09-30
·
Updated
2026-10-01
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Kiteworks Core versions prior to 9.5.1
Description
Content Injection occurs due to insufficient validation of a URL parameter in the PDF viewer. This flaw allows an attacker-controlled document to be loaded and displayed under the trust of the legitimate application domain, which may increase the credibility of phishing attempts using malicious links embedded in the content.
Recommendations
Update Kiteworks Core to version 9.5.1 or later.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kiteworks Core