CVE-2026-102124
MEDIUM
NVD
CVSS Score
6.5
Severity
MEDIUM
Published
Sep 30, 2026
Vendor
unknown
Description
A Kiteworks appliance setup interface did not enforce authentication once the appliance had completed initial configuration. An unauthenticated attacker with network access to the appliance could read and modify a limited set of setup records, including a contact name and email address captured during initial configuration.