Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kiteworks
Kiteworks core |
|
| Vendors & Products |
Kiteworks
Kiteworks core |
Wed, 30 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated administrator could cause the server to issue requests to, and interact with, internal network services that are not meant to be reachable through this interface. On its own this did not result in code execution. | |
| Title | Kiteworks Core Server-Side Request Forgery through CRLF Injection | |
| Weaknesses | CWE-93 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2026-09-30T20:08:34.493Z
Reserved: 2026-09-28T17:39:13.564Z
Link: CVE-2026-102145
No data.
Status : Awaiting Analysis
Published: 2026-09-30T21:17:03.390
Modified: 2026-10-01T02:17:43.350
Link: CVE-2026-102145
No data.
OpenCVE Enrichment
Updated: 2026-10-01T06:15:14Z
