VYPR

Kiteworks appliance

by Kiteworks

CVEs (3)

  • CVE-2026-102125HigSep 30, 2026
    risk 0.57cvss 8.8epss —

    The sandbox that isolates document conversion on a Kiteworks appliance did not fully confine the code running inside it. Code already executing within that sandbox could potentially escape its confinement and act with the privileges of the service account that runs the…

  • CVE-2026-102142HigSep 30, 2026
    risk 0.47cvss 7.2epss —

    A system notification template on the Kiteworks appliance was rendered by a template engine that evaluated expressions contained in the stored template body. An authenticated System Administrator could potentially store a crafted template that executed operating-system commands…

  • CVE-2026-102124MedSep 30, 2026
    risk 0.42cvss 6.5epss —

    A Kiteworks appliance setup interface did not enforce authentication once the appliance had completed initial configuration. An unauthenticated attacker with network access to the appliance could read and modify a limited set of setup records, including a contact name and email…