Export limit exceeded: 16890 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (87 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-102126 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 8.1 High |
| A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an administrator holding only a single, narrowly scoped delegated permission to store crafted content that later executes arbitrary JavaScript in the authenticated session of a System Administrator who views the affected page. This could have permitted the lower-privileged administrator to escalate to full administrative control of the tenant, including the creation of a new administrative account. | ||||
| CVE-2026-102132 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 7.2 High |
| An administrative import function in Kiteworks Core did not verify that the requesting administrator was entitled to create the privileged integration credential being imported. A delegated administrator holding a single narrowly scoped administrative permission could therefore obtain full system administrator privileges, without any action by an existing system administrator. | ||||
| CVE-2026-102134 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 5.4 Medium |
| Kiteworks Core did not apply its gateway-level API security controls to every request authenticated through the platform's central authentication service. An authenticated user could reach REST API functionality over a request path on which those controls, including enforcement of signed-out and revoked sessions, were not applied. | ||||
| CVE-2026-102123 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 7.4 High |
| A Kiteworks appliance setup interface did not confine a user-supplied file path to its intended directory, which could allow an unauthenticated attacker to write a file to any location writable by the affected service account, potentially compromising the integrity of the appliance or rendering it unavailable until an operator intervenes. Exploitation requires network access to the affected interface, which is not reachable on a fully configured appliance in its default configuration; reaching it depends on either the transient window while an appliance is first being provisioned or a non-default appliance configuration. | ||||
| CVE-2026-102122 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 4.3 Medium |
| Kiteworks did not correctly enforce which roles a shared folder's manager was permitted to assign. In a default configuration, an authenticated user holding the Manager role on a folder could grant the Owner role to themselves or to other members of that folder. | ||||
| CVE-2026-102120 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 8.8 High |
| A privilege escalation vulnerability in Kiteworks could have allowed an attacker who had already obtained code execution on one node of a clustered Kiteworks deployment to run operating system commands with elevated privileges on another node of the same cluster. Insufficient input validation in an internal cluster management function let attacker-supplied values reach a privileged execution context; exploitation requires existing access to a node in the cluster, and the affected function is not reachable from outside the cluster. | ||||
| CVE-2026-102118 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 7.8 High |
| A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an existing shell under a low-privileged service account to escalate to root privileges on the appliance. | ||||
| CVE-2026-102115 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 9.8 Critical |
| Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who knew the email address of a user with a locally stored password could potentially reset that account's password without access to the emailed reset link and then authenticate as that user, including where the account holds administrative privileges. | ||||
| CVE-2026-102114 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 7.2 High |
| A command injection vulnerability in Kiteworks could allow a high-privileged authenticated administrator to execute arbitrary operating-system commands as root on the affected appliance node. Successful exploitation requires an administrative account with elevated privileges. | ||||
| CVE-2026-102113 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 7.8 High |
| A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root. A privileged routine did not safely handle a filesystem path that the lower-privileged account could influence, allowing the attacker to cause a root-owned operation to run arbitrary commands with the highest privileges. Exploitation requires existing local access to that service account. | ||||
| CVE-2026-102112 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 7.8 High |
| A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root and run arbitrary commands with the highest privileges. Exploitation requires existing local access to that service account. | ||||
| CVE-2026-102150 | 2 Accellion, Kiteworks | 2 Kiteworks, Secure Data Forms | 2026-10-07 | 7.2 High |
| A function in the Kiteworks Advanced Forms component was reachable without authentication. An unauthenticated attacker could potentially use it to carry out a limited set of internal service operations on the Kiteworks platform; it did not permit access to user accounts, stored files, or form submissions. | ||||
| CVE-2026-102111 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 4.9 Medium |
| Kiteworks did not enforce the maximum permitted value for a configurable security-policy setting. An authenticated administrator could set this value outside its intended range so that the associated control never activated, while the control continued to appear enabled in the administrative interface and audit log, allowing it to be silently rendered ineffective. | ||||
| CVE-2026-102107 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 4.6 Medium |
| Kiteworks Core contains a business logic flaw in a Kiteworks file-request feature allowed an authenticated user to send a request that appeared to originate from another user, because the server did not verify that the requester was authorized to act as the specified account. This could be used to solicit files or information from a recipient under a trusted identity; exploitation requires the feature to be enabled for the attacker's profile and the targeted recipient to act on the request. | ||||
| CVE-2026-102101 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 8.1 High |
| Kiteworks Core before version 9.5.0 is vulnerable to Deserialization of Untrusted Data. A deserialization weakness in Kiteworks Core could, under certain conditions, allow crafted data to be deserialized unsafely, potentially resulting in remote code execution on the appliance. Exploitation depends on an attacker first being able to influence the affected data, so this issue is not exploitable on its own. | ||||
| CVE-2026-102100 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 8.7 High |
| Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-Site Scripting. A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an authenticated user to submit content that, when later viewed by another user, executes arbitrary JavaScript in that user's authenticated session. This could be used to perform actions on the victim's behalf and may have permitted account takeover, including of higher-privileged users. Exploitation requires the victim to view the attacker-supplied content. | ||||
| CVE-2026-102099 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 7.2 High |
| Kiteworks Core before version 9.5.0 is vulnerable to Arbitrary File Write. An improper restriction of a user-supplied file path in a Kiteworks administrative export feature could allow an authenticated administrator to write a file to an arbitrary location on the underlying host, potentially leading to command execution on the appliance. Exploitation requires an existing, authenticated administrative account with access to the affected export function. | ||||
| CVE-2026-102098 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 7.2 High |
| Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection. A stored SQL injection vulnerability in a Kiteworks administrative reporting feature could allow an authenticated administrator to read sensitive data from the underlying database and to affect the availability of the service. Exploitation requires an existing, authenticated administrative account with access to the affected reporting function. | ||||
| CVE-2026-102096 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 7.2 High |
| Kiteworks Core before version 9.5.0 is vulnerable to OS Command Injection that allows an authenticated administrator to upload a configuration package whose contents were not sufficiently validated before being processed. A crafted package could cause the underlying system to execute arbitrary operating-system commands, potentially with elevated privileges, on the affected appliance. | ||||
| CVE-2026-102093 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 7.2 High |
| Kiteworks Core before version 9.5.0 is vulnerable to Improper Privilege Management and does not correctly enforce restrictions on role assignment, which could allow an authenticated administrative user with limited, non-Sysadmin role-management permissions to elevate another user to full system-administrator privileges beyond those the administrative user was authorized to grant. | ||||