CVE-2026-102126: Kiteworks Core Stored Cross-site Scripting (XSS)

Published Sep 30, 2026
·
Updated

A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an administrator holding only a single, narrowly scoped delegated permission to store crafted content that later executes arbitrary JavaScript in the authenticated session of a System Administrator who views the affected page. This could have permitted the lower-privileged administrator to escalate to full administrative control of the tenant, including the creation of a new administrative account.

Affected Software

1 affected component
Kiteworks Core

Event History

Sep 30, 2026
CVE Published
via MITRE·08:15 PM
Data Sourced
via MITRE·08:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What level of access would an attacker need to initiate exploitation?

The attacker would need an administrator account with only a single, narrowly scoped delegated permission that allows them to store crafted content.

2

What user interaction is required for the stored content to have an effect?

A System Administrator must view the affected page while authenticated. The crafted content can then execute JavaScript in that administrator's authenticated session.

3

What could an attacker achieve after successful exploitation?

The lower-privileged administrator could escalate to full administrative control of the tenant, including creating a new administrative account.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203