CVE-2026-102098: Kiteworks Core SQL Injection
Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection. A stored SQL injection vulnerability in a Kiteworks administrative reporting feature could allow an authenticated administrator to read sensitive data from the underlying database and to affect the availability of the service. Exploitation requires an existing, authenticated administrative account with access to the affected reporting function.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Kiteworks Coreto a version that resolves this vulnerability.Fixed in 9.5.0
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
Exploitation requires an existing authenticated Kiteworks administrator account that can access the affected administrative reporting function. It is not described as exploitable by unauthenticated users or non-administrative accounts.
Which deployments are affected?
Kiteworks Core versions before 9.5.0 are affected. The vulnerability is in an administrative reporting feature, so exposure depends on administrators having access to that function.
What can an attacker do if they successfully exploit it?
An authenticated administrator could use the stored SQL injection to read sensitive data from the underlying database and affect service availability.