HIGH 7.5 NVD
CVE-2026-102143
An unauthenticated attacker could cause a file with attacker-controlled content to be written to the appliance filesystem through an administrative upload handl
An unauthenticated attacker could cause a file with attacker-controlled content to be written to the appliance filesystem through an administrative upload handler that did not properly authenticate the request. This did not by itself result in code execution, which would require a separate vulnerability to place the file in an executable location.
References
- https://github.com/kiteworks/security-advisories/security/advisories/GHSA-3p9g-jh62-8f89
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-
This high severity vulnerability with a CVSS score of 7.5 was published on 2026-09-30 via NVD.
vulnfeed aggregates 9519 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.