{"api_version":"1","generated_at":"2026-10-04T02:48:35+00:00","cve":"CVE-2026-102140","urls":{"html":"https://cve.report/CVE-2026-102140","api":"https://cve.report/api/cve/CVE-2026-102140.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-102140","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-102140"},"summary":{"title":"Kiteworks Core Insufficient Verification of Data Authenticity","description":"An authenticated administrator could initiate an administrative import using a file whose contents were not fully verified, because the import validated only the file's header rather than the complete file. This could allow unverified or forged content to be accepted and processed, affecting the integrity of the imported data.","state":"PUBLISHED","assigner":"cisa-cg","published_at":"2026-09-30 21:17:02","updated_at":"2026-10-01 14:17:18"},"problem_types":["CWE-345","CWE-345 CWE-345 Insufficient Verification of Data Authenticity"],"metrics":[{"version":"3.1","source":"9119a7d8-5eab-497f-8521-727c672e3725","type":"Secondary","score":"4.9","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"4.9","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.9,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N","version":"3.1"}}],"references":[{"url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json","name":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json","refsource":"9119a7d8-5eab-497f-8521-727c672e3725","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/kiteworks/security-advisories/security/advisories/GHSA-wfxj-p5jc-jqjw","name":"https://github.com/kiteworks/security-advisories/security/advisories/GHSA-wfxj-p5jc-jqjw","refsource":"9119a7d8-5eab-497f-8521-727c672e3725","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-102140","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102140","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Kiteworks","product":"Core","version":"affected 9.5.1 custom","platforms":[]},{"source":"CNA","vendor":"Kiteworks","product":"Core","version":"unaffected 9.5.1","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Supr4s, https://yeswehack.com/hunters/Supr4s","lang":"en"},{"source":"CNA","value":"wlayzz, https://yeswehack.com/hunters/wlayzz","lang":"en"},{"source":"CNA","value":"Icare, https://yeswehack.com/hunters/icare","lang":"en"},{"source":"CNA","value":"truff, https://yeswehack.com/hunters/truff","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"102140","cve":"CVE-2026-102140","epss":"0.001400000","percentile":"0.027840000","score_date":"2026-10-03","updated_at":"2026-10-04 00:03:18"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-102140","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-10-01T13:26:16.635969Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-10-01T13:37:07.652Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unknown","product":"Core","vendor":"Kiteworks","versions":[{"lessThan":"9.5.1","status":"affected","version":"0","versionType":"custom"},{"status":"unaffected","version":"9.5.1"}]}],"credits":[{"lang":"en","value":"Supr4s, https://yeswehack.com/hunters/Supr4s"},{"lang":"en","value":"wlayzz, https://yeswehack.com/hunters/wlayzz"},{"lang":"en","value":"Icare, https://yeswehack.com/hunters/icare"},{"lang":"en","value":"truff, https://yeswehack.com/hunters/truff"}],"datePublic":"2026-09-30T00:00:00.000Z","descriptions":[{"lang":"en","value":"An authenticated administrator could initiate an administrative import using a file whose contents were not fully verified, because the import validated only the file's header rather than the complete file. This could allow unverified or forged content to be accepted and processed, affecting the integrity of the imported data."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.9,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-345","description":"CWE-345 Insufficient Verification of Data Authenticity","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-30T20:11:07.754Z","orgId":"9119a7d8-5eab-497f-8521-727c672e3725","shortName":"cisa-cg"},"references":[{"name":"url","url":"https://github.com/kiteworks/security-advisories/security/advisories/GHSA-wfxj-p5jc-jqjw"},{"name":"url","url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"}],"title":"Kiteworks Core Insufficient Verification of Data Authenticity","x_generator":{"engine":"VINCE-NT 1.15.0+build.145"}}},"cveMetadata":{"assignerOrgId":"9119a7d8-5eab-497f-8521-727c672e3725","assignerShortName":"cisa-cg","cveId":"CVE-2026-102140","datePublished":"2026-09-30T20:11:07.754Z","dateReserved":"2026-09-28T17:39:13.564Z","dateUpdated":"2026-10-01T13:37:07.652Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-30 21:17:02","lastModifiedDate":"2026-10-01 14:17:18","problem_types":["CWE-345","CWE-345 CWE-345 Insufficient Verification of Data Authenticity"],"metrics":{"cvssMetricV31":[{"source":"9119a7d8-5eab-497f-8521-727c672e3725","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-10-01T13:26:16.635969Z","id":"CVE-2026-102140","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"102140","Ordinal":"1","Title":"Kiteworks Core Insufficient Verification of Data Authenticity","CVE":"CVE-2026-102140","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"102140","Ordinal":"1","NoteData":"An authenticated administrator could initiate an administrative import using a file whose contents were not fully verified, because the import validated only the file's header rather than the complete file. This could allow unverified or forged content to be accepted and processed, affecting the integrity of the imported data.","Type":"Description","Title":"Kiteworks Core Insufficient Verification of Data Authenticity"}]}}}