Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-102090

Kiteworks Core before version 9.5.1 is vulnerable to Content Injection. A URL parameter in the PDF viewer was insufficiently validated, allowing an attacker-controlled document to be loaded and displayed under the trust of the legitimate application domain. This could increase the credibility of phishing attempts relying on malicious links embedded in the displayed content.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 8.6%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2026-102090


Contact Us

Shodan ® - All rights reserved