CVE-2026-102110: Missing authentication on a Kiteworks appliance setup function
An endpoint used during initial appliance setup did not require authentication and did not correctly enforce its intended state precondition, so during the initial activation window an unauthenticated network attacker could repeatedly re-trigger the privileged activation process. This could disrupt setup and leave the appliance in an incompletely configured state. The issue is only reachable while an appliance is being activated for the first time and not yet fully configured.
Affected Software
Event History
Frequently Asked Questions
Which appliances are exposed to this issue?
Only appliances in their first-time activation window, before they are fully configured, are affected. Appliances that have completed initial setup are not reachable through the vulnerable condition.
What does an attacker need to exploit it?
An attacker needs network access to the appliance while initial activation is in progress. No authentication or user interaction is required, but the attack has high complexity because it depends on that limited setup state.
What is the practical impact of successful exploitation?
An attacker can repeatedly trigger the privileged activation process, disrupting setup and potentially leaving the appliance incompletely configured. The provided information indicates integrity impact, not confidentiality or availability impact.
What can be done if patching is not immediately possible?
Limit network access to appliances during their initial activation and complete setup as promptly as possible. The vulnerable endpoint is only reachable before the appliance is fully configured.