CVE-2026-102145

medium

Description

An authenticated administrator could cause the server to issue requests to, and interact with, internal network services that are not meant to be reachable through this interface. On its own this did not result in code execution.

References

https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json

https://github.com/kiteworks/security-advisories/security/advisories/GHSA-h97r-j99c-q8xc

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-90381

Details

Source: Mitre, NVD

Published: 2026-09-30

Updated: 2026-10-01

Risk Information

CVSS v2

Base Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:M/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 6.6

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L

Severity: Medium

EPSS

EPSS: 0.00282