Vulnerability Details CVE-2026-102150
A function in the Kiteworks Advanced Forms component was reachable without authentication. An unauthenticated attacker could potentially use it to carry out a limited set of internal service operations on the Kiteworks platform; it did not permit access to user accounts, stored files, or form submissions.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 14.8%
CVSS Severity
CVSS v3 Score 7.2