CVE-2026-102090
Received Received - Intake

Content Injection Vulnerability in Kiteworks Core

Vulnerability report for CVE-2026-102090, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Description

Kiteworks Core before version 9.5.1 is vulnerable to Content Injection. A URL parameter in the PDF viewer was insufficiently validated, allowing an attacker-controlled document to be loaded and displayed under the trust of the legitimate application domain. This could increase the credibility of phishing attempts relying on malicious links embedded in the displayed content.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
kiteworks core to 9.5.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-601 The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Kiteworks Core before version 9.5.1 has a vulnerability called Content Injection. A URL parameter in the PDF viewer was not properly checked, allowing an attacker to load and display a malicious document under the legitimate application domain. This makes phishing attempts more convincing by showing malicious content under a trusted domain.

Detection Guidance

Detection may involve checking for unauthorized PDF viewer URL parameters or unusual document loading behavior in Kiteworks Core versions before 9.5.1. Monitor network traffic for suspicious PDF viewer requests or unexpected domain redirections.

Impact Analysis

This vulnerability could trick you into clicking a malicious link, as the displayed content appears to come from a trusted source. Attackers might use it to steal sensitive information or spread malware through seemingly legitimate documents.

Compliance Impact

The vulnerability could potentially undermine compliance with GDPR and HIPAA by enabling phishing attacks that appear credible due to the malicious content being displayed under the legitimate application domain. This may lead to unauthorized access to sensitive data or misrepresentation of trusted sources, violating data protection and privacy requirements.

Mitigation Strategies

Upgrade Kiteworks Core to version 9.5.1 or later immediately. If upgrading is not possible, restrict access to the PDF viewer functionality or implement additional input validation for URL parameters.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102090. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart