VDB
CVE-2026-102120
CVE-2026-102120
PUBLISHED
CVSS 8.8 HIGH
Reported by cisa-cg · Published September 30, 2026
A privilege escalation vulnerability in Kiteworks could have allowed an attacker who had already obtained code execution on one node of a clustered Kiteworks deployment to run operating system commands with elevated privileges on another node of the same cluster. Insufficient input validation in an internal cluster management function let attacker-supplied values reach a privileged execution context; exploitation requires existing access to a node in the cluster, and the affected function is not reachable from outside the cluster.
Risk Scores
CVSS 3.1
8.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kiteworks | Core | 0, 9.5.1 |
| Kiteworks | Core | 0, 9.5.1, 0 |
Timeline
- Sep 30, 2026 Coalition ESS Score
- Sep 30, 2026 CVE Published
- Oct 1, 2026 EPSS Score
- Oct 1, 2026 CVE Updated
- Oct 2, 2026 EPSS Score