CVE-2026-102098
Received Received - Intake

SQL Injection in Kiteworks Core

Vulnerability report for CVE-2026-102098, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Description

Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection. A stored SQL injection vulnerability in a Kiteworks administrative reporting feature could allow an authenticated administrator to read sensitive data from the underlying database and to affect the availability of the service. Exploitation requires an existing, authenticated administrative account with access to the affected reporting function.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
kiteworks core to 9.5.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Kiteworks Core before version 9.5.0 has a stored SQL injection vulnerability in an administrative reporting feature. This allows an authenticated admin to read sensitive database data and potentially disrupt service availability.

Detection Guidance

Detection requires checking for SQL injection attempts in Kiteworks Core administrative reporting features. Monitor database logs for unusual queries or errors. Review access logs for administrative accounts accessing reporting functions. No specific commands are provided in the context.

Impact Analysis

If you are an admin using Kiteworks Core before 9.5.0, an attacker with admin access could exploit this to steal sensitive data or cause service outages. Users may face data breaches or disrupted access to the platform.

Compliance Impact

This vulnerability could lead to unauthorized data access, violating GDPR (data protection) and HIPAA (health data privacy) requirements. Organizations may face legal penalties, fines, or reputational damage due to non-compliance.

Mitigation Strategies

Upgrade Kiteworks Core to version 9.5.0 or later immediately. Restrict administrative account access to only necessary functions. Implement network segmentation to limit exposure of administrative interfaces. Monitor database activity for suspicious queries.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102098. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart