CVE-2026-102090

CVE-2026-102090 published: Kiteworks Core before version 9.5.1 is vulnerable to Content Injection. A URL parameter in the PDF viewer was insufficiently validated, allowing an attacker-controlled document to be loaded and displayed under the trust of the legitimate application domain....

View full NVD advisory → ← Back to CVE watch