VDB

CVE-2026-102133

CVE-2026-102133 PUBLISHED CVSS 6.6 MEDIUM

Reported by cisa-cg · Published September 30, 2026

An optional, separately licensed repository-connector feature in Kiteworks Core did not neutralize special characters in a user-supplied path before passing it to an external command. An authenticated system administrator could inject additional commands and write arbitrary content to files owned by the service account running the connector, enabling code execution in that account's context; exploitation additionally requires network egress from the appliance to a system under the attacker's control.

Risk Scores

CVSS 3.1
6.6
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
KiteworksCore0, 9.5.1
KiteworksCore0, 9.5.1, 0

Timeline

  • Sep 30, 2026 Coalition ESS Score
  • Sep 30, 2026 CVE Published
  • Oct 1, 2026 EPSS Score
  • Oct 1, 2026 CVE Updated
  • Oct 2, 2026 EPSS Score
  • Oct 6, 2026 EPSS Score

References

  • url vendor-advisory
  • url third-party-advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›