CVE-2026-102134
Received Received - Intake

Kiteworks Core API Security Bypass Vulnerability

Vulnerability report for CVE-2026-102134, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Description

Kiteworks Core did not apply its gateway-level API security controls to every request authenticated through the platform's central authentication service. An authenticated user could reach REST API functionality over a request path on which those controls, including enforcement of signed-out and revoked sessions, were not applied.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
kiteworks core *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-420 The product protects a primary channel, but it does not use the same level of protection for an alternate channel.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Kiteworks Core failed to enforce gateway-level API security controls for all requests authenticated via its central service. This allowed authenticated users to access REST API functions through paths where controls like session validation were not applied.

Impact Analysis

An attacker with valid credentials could exploit this to access unauthorized API functions, potentially leading to data leaks or unauthorized actions. The impact is limited to authenticated users but could compromise sensitive operations.

Compliance Impact

This vulnerability could violate compliance requirements by allowing unauthorized access to sensitive data or operations. GDPR and HIPAA mandate strict access controls, which this flaw undermines by failing to enforce session validation.

Mitigation Strategies

Apply gateway-level API security controls to all authenticated requests. Ensure enforcement of signed-out and revoked sessions across all API paths. Review and update authentication service configurations to cover all REST API endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102134. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart