CVE-2026-102123: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Kiteworks Core
CVE-2026-102123 is a path traversal vulnerability in the Kiteworks Core appliance setup interface. It allows an unauthenticated attacker to write files to arbitrary locations writable by the service account. Exploitation requires network access to a setup interface that is normally unreachable in default configurations, limiting exposure to initial provisioning or non-default setups. The vulnerability can compromise appliance integrity or cause denial of service until manual intervention. It affects Kiteworks Core versions prior to 9.5.0.
AI Analysis
Technical Summary
The vulnerability involves improper limitation of a pathname to a restricted directory (CWE-22) in the Kiteworks Core appliance setup interface. An attacker can supply a crafted file path to write files outside the intended directory. This can lead to integrity compromise or unavailability of the appliance. Network access to the vulnerable interface is required, but this interface is typically inaccessible on fully configured appliances in default mode. The affected versions are all Kiteworks Core versions from initial releases up to but not including 9.5.0.
Potential Impact
An unauthenticated attacker with network access to the setup interface can write files arbitrarily within locations writable by the service account. This can compromise the integrity of the appliance or render it unavailable until an operator intervenes. The attack surface is limited because the vulnerable interface is not reachable in default configurations except during initial provisioning or if the appliance is configured non-default.
Mitigation Recommendations
No official patch or remediation details are provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the vulnerable interface is normally unreachable in default configurations, ensuring the appliance is fully configured and not in provisioning state reduces exposure. Avoid non-default configurations that expose the setup interface to untrusted networks.
CVE-2026-102123: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Kiteworks Core
Description
CVE-2026-102123 is a path traversal vulnerability in the Kiteworks Core appliance setup interface. It allows an unauthenticated attacker to write files to arbitrary locations writable by the service account. Exploitation requires network access to a setup interface that is normally unreachable in default configurations, limiting exposure to initial provisioning or non-default setups. The vulnerability can compromise appliance integrity or cause denial of service until manual intervention. It affects Kiteworks Core versions prior to 9.5.0.
CVSS v3.1
Score 7.4high
Affected software
Kiteworks
Core
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability involves improper limitation of a pathname to a restricted directory (CWE-22) in the Kiteworks Core appliance setup interface. An attacker can supply a crafted file path to write files outside the intended directory. This can lead to integrity compromise or unavailability of the appliance. Network access to the vulnerable interface is required, but this interface is typically inaccessible on fully configured appliances in default mode. The affected versions are all Kiteworks Core versions from initial releases up to but not including 9.5.0.
Potential Impact
An unauthenticated attacker with network access to the setup interface can write files arbitrarily within locations writable by the service account. This can compromise the integrity of the appliance or render it unavailable until an operator intervenes. The attack surface is limited because the vulnerable interface is not reachable in default configurations except during initial provisioning or if the appliance is configured non-default.
Mitigation Recommendations
No official patch or remediation details are provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the vulnerable interface is normally unreachable in default configurations, ensuring the appliance is fully configured and not in provisioning state reduces exposure. Avoid non-default configurations that expose the setup interface to untrusted networks.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- cisa-cg
- Date Reserved
- 2026-09-28T17:39:13.563Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abd724d2a4e24523d8ebe0a
Added to database: 09/30/2026, 20:34:21 UTC
Last enriched: 09/30/2026, 21:04:12 UTC
Last updated: 10/01/2026, 04:46:42 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.