← back
CVE-2026-102145mediumCWE-93

Kiteworks Core Server-Side Request Forgery through CRLF Injection

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.6epss 0.3%
exploitation probability
0.3%top 81% of all CVEs
observed exploitation
nono source reports it
An authenticated administrator could cause the server to issue requests to, and interact with, internal network services that are not meant to be reachable through this interface. On its own this did not result in code execution.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
Affected products
Kiteworks · Core