NCSC | Security Advisories
Bekijk RSS-feed

Security Advisories

Download

Security Advisory; NCSC-2026-0408 [1.0.0]

Security Advisory
NCSC-2026-0408 [1.0.0]
Publicatie
08-10-2026 13:21 (Europe/Amsterdam)
Prioriteit
Normaal
Betreft
Kwetsbaarheden verholpen in Kiteworks

Kenmerken

  • Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
  • Improper Link Resolution Before File Access ('Link Following')
  • External Control of File Name or Path
  • Improper Neutralization of Special Elements used in a Command ('Command Injection')
  • Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
  • Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
  • Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
  • XML Injection (aka Blind XPath Injection)
  • Improper Neutralization of CRLF Sequences ('CRLF Injection')
  • Improper Control of Generation of Code ('Code Injection')
  • Improper Handling of Case Sensitivity
  • Execution with Unnecessary Privileges
  • Incorrect Privilege Assignment
  • Missing Authentication for Critical Function
  • Unprotected Alternate Channel
  • Unrestricted Upload of File with Dangerous Type
  • Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
  • Deserialization of Untrusted Data
  • URL Redirection to Untrusted Site ('Open Redirect')
  • Improper Restriction of XML External Entity Reference
  • Authorization Bypass Through User-Controlled Key
  • Weak Password Recovery Mechanism for Forgotten Password
  • Improper Isolation or Compartmentalization
  • Always-Incorrect Control Flow Implementation
  • Reliance on Untrusted Inputs in a Security Decision
  • Incorrect Authorization
  • Server-Side Request Forgery (SSRF)
  • Improper Verification of Source of a Communication Channel
  • Improper Validation of Specified Quantity in Input
  • Improper Neutralization of Special Elements Used in a Template Engine

Omschrijving

Kiteworks heeft meerdere kwetsbaarheden verholpen in de Kiteworks productlijn.

De kwetsbaarheden in Kiteworks betreffen diverse componenten en functionaliteiten binnen de producten.

  • Geauthenticeerde beheerders kunnen onder andere misbruik maken van onvoldoende validatie in import- en exportfuncties, wat leidt tot het schrijven van bestanden op willekeurige locaties en het uitvoeren van arbitrary code.
  • Er zijn meerdere gevallen van privilege-escalatie waarbij gebruikers met beperkte rechten hun privileges kunnen verhogen tot systeembeheerder.
  • Verder zijn er kwetsbaarheden die het mogelijk maken om via Server-Side Request Forgery (SSRF) ongeautoriseerde verzoeken naar interne netwerken te sturen, wat toegang tot beschermde interne bronnen kan geven.
  • Cross-site scripting (XSS) kwetsbaarheden maken het mogelijk om kwaadaardige scripts uit te voeren in de context van andere gebruikers, wat sessieovername kan veroorzaken.
  • SQL-injectieproblemen in administratieve functies kunnen leiden tot ongeautoriseerde toegang tot databasegegevens.
  • Daarnaast zijn er kwetsbaarheden in authenticatiemechanismen, waaronder bypasses en het resetten van wachtwoorden zonder juiste verificatie, wat ongeautoriseerde accounttoegang mogelijk maakt.
  • Sommige kwetsbaarheden betreffen ook de cluster- en appliance-omgevingen, waarbij command execution en privilege-escalatie tussen nodes mogelijk is.
  • Verder zijn er problemen met onvoldoende validatie van uploads, configuratiebestanden en certificaattoewijzingen, wat kan leiden tot systeemcompromittering of het onderscheppen van versleutelde communicatie.
  • Ten slotte zijn er kwetsbaarheden die resource exhaustion kunnen veroorzaken, wat de beschikbaarheid van de systemen kan beïnvloeden.

Exploitatie van deze kwetsbaarheden vereist in veel gevallen authentificatie met beheerdersrechten, maar er zijn ook kwetsbaarheden die zonder authenticatie kunnen worden misbruikt, met name tijdens de initiële setup of via onbeveiligde interfaces. Omdat kwetsbaarheden die zonder voorafgaande authenticatie kunnen worden misbruikt mogelijk kunnen leiden tot verhoogde rechten, is het niet uitgesloten dat de kwetsbaarheden in keten kunnen worden misbruikt en kunnen leiden tot uitvoer van handelingen onder beheerdersrechten.

Oplossingen

Kiteworks heeft updates uitgebracht om de kwetsbaarheden in de Kiteworks productlijn te verhelpen. Zie bijgevoegde referenties voor meer informatie.

Referenties

CVE's

Producten

Kiteworks
Core
Email Protection Gateway
Kiteworks
Secure Data Forms

Disclaimer

The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this page to enhance access to its information and security advisories. The use of this security advisory is subject to the following terms and conditions: NCSC-NL makes every reasonable effort to ensure that the content of this page is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or continuous keeping up-to-date. The information contained in this security advisory is intended solely for the purpose of providing general information to professional users. No rights can be derived from the information provided therein. NCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of this security advisory. This includes damage resulting from the inaccuracy of incompleteness of the information contained in the advisory. This security advisory is subject to Dutch law. All disputes related to or arising from the use of this advisory will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings.