Loading market data...
← Back to CVE feed

CVE-2026-102090

MEDIUM CVSS 4.3 View on NVD ↗

Description

Kiteworks Core before version 9.5.1 is vulnerable to Content Injection. A URL parameter in the PDF viewer was insufficiently validated, allowing an attacker-controlled document to be loaded and displayed under the trust of the legitimate application domain. This could increase the credibility of phishing attempts relying on malicious links embedded in the displayed content.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Published: Sep 30, 2026 21:16 UTC Modified: Oct 01, 2026 14:17 UTC