{"api_version":"1","generated_at":"2026-10-01T11:59:20+00:00","cve":"CVE-2026-102145","urls":{"html":"https://cve.report/CVE-2026-102145","api":"https://cve.report/api/cve/CVE-2026-102145.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-102145","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-102145"},"summary":{"title":"Kiteworks Core Server-Side Request Forgery through CRLF Injection","description":"An authenticated administrator could cause the server to issue requests to, and interact with, internal network services that are not meant to be reachable through this interface. On its own this did not result in code execution.","state":"PUBLISHED","assigner":"cisa-cg","published_at":"2026-09-30 21:17:03","updated_at":"2026-10-01 02:17:43"},"problem_types":["CWE-93","CWE-93 CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')"],"metrics":[{"version":"3.1","source":"9119a7d8-5eab-497f-8521-727c672e3725","type":"Secondary","score":"6.6","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L","baseScore":6.6,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"6.6","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":6.6,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"HIGH","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L","version":"3.1"}}],"references":[{"url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json","name":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json","refsource":"9119a7d8-5eab-497f-8521-727c672e3725","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/kiteworks/security-advisories/security/advisories/GHSA-h97r-j99c-q8xc","name":"https://github.com/kiteworks/security-advisories/security/advisories/GHSA-h97r-j99c-q8xc","refsource":"9119a7d8-5eab-497f-8521-727c672e3725","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-102145","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102145","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Kiteworks","product":"Core","version":"affected 9.5.1 custom","platforms":[]},{"source":"CNA","vendor":"Kiteworks","product":"Core","version":"unaffected 9.5.1","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Supr4s, https://yeswehack.com/hunters/supr4s","lang":"en"},{"source":"CNA","value":"wlayzz, https://yeswehack.com/hunters/wlayzz","lang":"en"},{"source":"CNA","value":"Icare, https://yeswehack.com/hunters/icare","lang":"en"},{"source":"CNA","value":"truff, https://yeswehack.com/hunters/truff","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unknown","product":"Core","vendor":"Kiteworks","versions":[{"lessThan":"9.5.1","status":"affected","version":"0","versionType":"custom"},{"status":"unaffected","version":"9.5.1"}]}],"credits":[{"lang":"en","value":"Supr4s, https://yeswehack.com/hunters/supr4s"},{"lang":"en","value":"wlayzz, https://yeswehack.com/hunters/wlayzz"},{"lang":"en","value":"Icare, https://yeswehack.com/hunters/icare"},{"lang":"en","value":"truff, https://yeswehack.com/hunters/truff"}],"datePublic":"2026-09-30T00:00:00.000Z","descriptions":[{"lang":"en","value":"An authenticated administrator could cause the server to issue requests to, and interact with, internal network services that are not meant to be reachable through this interface. On its own this did not result in code execution."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":6.6,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"HIGH","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-93","description":"CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-30T20:08:34.493Z","orgId":"9119a7d8-5eab-497f-8521-727c672e3725","shortName":"cisa-cg"},"references":[{"name":"url","url":"https://github.com/kiteworks/security-advisories/security/advisories/GHSA-h97r-j99c-q8xc"},{"name":"url","tags":["third-party-advisory"],"url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"}],"title":"Kiteworks Core Server-Side Request Forgery through CRLF Injection","x_generator":{"engine":"VINCE-NT 1.15.0+build.145"}}},"cveMetadata":{"assignerOrgId":"9119a7d8-5eab-497f-8521-727c672e3725","assignerShortName":"cisa-cg","cveId":"CVE-2026-102145","datePublished":"2026-09-30T20:08:34.493Z","dateReserved":"2026-09-28T17:39:13.564Z","dateUpdated":"2026-09-30T20:08:34.493Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-30 21:17:03","lastModifiedDate":"2026-10-01 02:17:43","problem_types":["CWE-93","CWE-93 CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')"],"metrics":{"cvssMetricV31":[{"source":"9119a7d8-5eab-497f-8521-727c672e3725","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L","baseScore":6.6,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.3,"impactScore":3.7}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"102145","Ordinal":"1","Title":"Kiteworks Core Server-Side Request Forgery through CRLF Injectio","CVE":"CVE-2026-102145","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"102145","Ordinal":"1","NoteData":"An authenticated administrator could cause the server to issue requests to, and interact with, internal network services that are not meant to be reachable through this interface. On its own this did not result in code execution.","Type":"Description","Title":"Kiteworks Core Server-Side Request Forgery through CRLF Injectio"}]}}}