CVE-2026-102145: Kiteworks Core Server-Side Request Forgery through CRLF Injection
An authenticated administrator could cause the server to issue requests to, and interact with, internal network services that are not meant to be reachable through this interface. On its own this did not result in code execution.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Exploitation requires an authenticated administrator. The vulnerability is therefore most relevant where administrative accounts may be compromised, misused, or accessible to untrusted users.
What access does an attacker gain through successful exploitation?
An attacker can cause Kiteworks Core to send requests to and interact with internal network services that are not intended to be reachable through the affected interface. The available information states that this issue alone does not result in code execution.
Is user interaction required to exploit the vulnerability?
No. The supplied vector indicates that no separate user interaction is required once an attacker has authenticated administrator privileges.