Kiteworks Core 中一个可选的、单独许可的 repository-connector(仓库连接器)功能,在将用户提供的路径传递给外部命令之前,未对特殊字符进行中和处理。经过身份验证的系统管理员可以注入额外命令,并向由运行该连接器的服务账户所拥有的文件写入任意内容,从而在该账户上下文中实现代码执行。此外,利用此漏洞还需要从设备向攻击者控制的系统发起网络出站连接。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102115 | 9.8 CRITICAL | Kiteworks Core Authentication Bypass in the Password Reset Workflow |
| CVE-2026-102149 | 9.4 CRITICAL | Kiteworks Email Protection Gateway Improper Access Control |
| CVE-2026-102147 | 9.3 CRITICAL | Kiteworks Core Administrative Account Takeover through Stored Cross-site Scripting (XSS) |
| CVE-2026-102104 | 9.1 CRITICAL | Kiteworks Email Protection Gateway server-side request forgery |
| CVE-2026-102095 | 9.1 CRITICAL | Kiteworks Email Protection Gateway server-side request forgery |
| CVE-2026-102102 | 9.1 CRITICAL | Kiteworks Email Protection Gateway server-side request forgery |
| CVE-2026-102105 | 9.1 CRITICAL | Kiteworks Email Protection Gateway server-side request forgery |
| CVE-2026-102103 | 9.1 CRITICAL | Kiteworks Email Protection Gateway server-side request forgery |
| CVE-2026-102106 | 9.1 CRITICAL | Kiteworks Email Protection Gateway improper authentication |
| CVE-2026-102120 | 8.8 HIGH | Kiteworks Core OS Command Injection |
| CVE-2026-102125 | 8.8 HIGH | Kiteworks Core Sandbox Escape |
| CVE-2026-102092 | 8.7 HIGH | Kiteworks Core stored XSS |
| CVE-2026-102100 | 8.7 HIGH | Kiteworks Core stored XSS |
| CVE-2026-102121 | 8.6 HIGH | Kiteworks Secure Data Forms Exposure of Sensitive Information to an Unauthorized Actor |
| CVE-2026-102126 | 8.1 HIGH | Kiteworks Core Stored Cross-site Scripting (XSS) |
| CVE-2026-102101 | 8.1 HIGH | Kiteworks Core deserialization of untrusted data |
| CVE-2026-102112 | 7.8 HIGH | Kiteworks Core Local Privilege Escalation |
| CVE-2026-102118 | 7.8 HIGH | Kiteworks Core before version 9.5.0 is vulnerable to Local Privilege Escalation |
| CVE-2026-102113 | 7.8 HIGH | Kiteworks Core Local Privilege Escalation |
| CVE-2026-102143 | 7.5 HIGH | Kiteworks Email Protection Gateway Unrestricted Upload of File with Dangerous Type |
Showing top 20 of 61 CVEs. View all on vendor page → →
No comments yet