CVE-2026-102111
Received Received - Intake

Kiteworks Security Policy Bypass via Misconfigured Setting

Vulnerability report for CVE-2026-102111, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Description

Kiteworks did not enforce the maximum permitted value for a configurable security-policy setting. An authenticated administrator could set this value outside its intended range so that the associated control never activated, while the control continued to appear enabled in the administrative interface and audit log, allowing it to be silently rendered ineffective.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
kiteworks kiteworks *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1284 The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Kiteworks failed to enforce the maximum value for a security-policy setting. An authenticated admin could set this value beyond its intended range, preventing the associated security control from activating while still showing as enabled in the interface and logs. This makes the control ineffective without detection.

Impact Analysis

This vulnerability could allow an attacker with admin access to bypass intended security controls, potentially leading to unauthorized data access or other malicious activities without triggering alerts or logs.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR, HIPAA, or other regulations by failing to enforce required security controls, potentially resulting in data breaches or unauthorized access.

Mitigation Strategies

Review the configurable security-policy setting to ensure it is set within the maximum permitted value. Verify that the control is functioning as intended by testing its activation. Update to a patched version if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102111. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart