External risk intelligence

Kiteworks Core Stored XSS Vulnerability Allows Administrator Account Takeover.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-102147

Kiteworks is a file sharing and managed file transfer platform designed specifically to be public-facing for external data exchange, making its administrative and user interfaces commonly accessible via the public internet.

Cross-site Scripting

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A stored cross-site scripting weakness has been identified in Kiteworks Core, potentially allowing an unauthenticated attacker to gain administrative control by executing JavaScript within an administrator's session.

  • Stored scripting allows attackers to inject code.
  • Gaining admin control could impact operations.
  • Confirm relevance and any potential exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could exploit this weakness by submitting specially crafted content to the Kiteworks Core platform. When an administrator later accesses the page displaying this content, the stored malicious script would execute within their browser session. This could grant the attacker administrative privileges, including the ability to create new administrator accounts.

  • No authentication required to initially submit content.
  • Vulnerable component is a web page viewed by administrators.
  • Risk is full administrative control and account creation.

Live Threat

Current exploitation, exposure, and threat context

A stored cross-site scripting vulnerability in Kiteworks Core could allow an unauthenticated attacker to inject malicious JavaScript. When an administrator views a page containing this crafted content, the JavaScript could execute within their authenticated session. This could potentially lead to an attacker gaining full administrative control over the affected system.

  • Administrative control and account creation at risk.
  • JavaScript execution within administrator sessions.
  • Attacker could gain full system administration.

Operational Fix

Recommended remediation, mitigation, and detection steps

This stored cross-site scripting (XSS) vulnerability in Kiteworks Core requires immediate attention from teams responsible for application security and platform management. The first step is to identify all instances of Kiteworks Core, determine their exposure, and assess business criticality to prioritize remediation efforts.

  • Application owners must address the vulnerability.
  • Verify Kiteworks Core exposure and criticality.
  • Plan remediation and vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Kiteworks Core and how is it used?

Kiteworks Core is a managed file transfer and secure file-sharing platform. Organizations use it to exchange sensitive data externally with partners and clients, often relying on it as a primary interface for public-facing data workflows.

What does CVE-2026-102147 mean in plain English?

This is a Stored Cross-Site Scripting (XSS) vulnerability, classified as CWE-79. It means an attacker can hide malicious code within the platform that stays there until an administrator views it. When that happens, the code runs in the admin's browser, potentially granting the attacker complete control over the system.

How does an attacker trigger this XSS vulnerability?

An attacker triggers the bug by submitting specially crafted content to the platform without needing a login. The vulnerability does not activate when standard users view the content; it only executes when a privileged administrator visits the specific page containing the injected script.

Is my Kiteworks instance at risk?

Halo Surface Signal indicates that Kiteworks platforms are frequently configured to be internet-facing for external data exchange. Because the administrative interface is often accessible via the public internet, you should assume a higher likelihood of exposure to external attackers.

What should I do to address CVE-2026-102147?

Start by identifying all deployed instances of Kiteworks Core within your environment. Once identified, evaluate their exposure level and business criticality to prioritize your response, then coordinate with your platform vendor for official remediation guidance.

References