OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102100

HIGH · CVSS 8.7 EPSS 0.22% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

Kiteworks Core versions prior to 9.5.0 are susceptible to a stored cross-site scripting vulnerability that allows authenticated users to inject malicious JavaScript, which executes in the context of another user's session. This could lead to unauthorized actions on behalf of the victim, potentially resulting in account takeover, including for users with elevated privileges. Organizations using affected versions should prioritize patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102100
Severity
HIGH
CVSS
8.7
EPSS
0.22%
Java

Original NVD Description

Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-Site Scripting. A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an authenticated user to submit content that, when later viewed by another user, executes arbitrary JavaScript in that user's authenticated session. This could be used to perform actions on the victim's behalf and may have permitted account takeover, including of higher-privileged users. Exploitation requires the victim to view the attacker-supplied content.

Related CVEs

Other vulnerabilities affecting the same vendor(s)