CVE-2026-102126: Kiteworks Core Stored Cross-site Scripting (XSS)
A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an administrator holding only a single, narrowly scoped delegated permission to store crafted content that later executes arbitrary JavaScript in the authenticated session of a System Administrator who views the affected page. This could have permitted the lower-privileged administrator to escalate to full administrative control of the tenant, including the creation of a new administrative account.
Affected Software
Event History
Frequently Asked Questions
What level of access would an attacker need to initiate exploitation?
The attacker would need an administrator account with only a single, narrowly scoped delegated permission that allows them to store crafted content.
What user interaction is required for the stored content to have an effect?
A System Administrator must view the affected page while authenticated. The crafted content can then execute JavaScript in that administrator's authenticated session.
What could an attacker achieve after successful exploitation?
The lower-privileged administrator could escalate to full administrative control of the tenant, including creating a new administrative account.