CVE-2026-102114

Summary

A command injection vulnerability in Kiteworks could allow a high-privileged authenticated administrator to execute arbitrary operating-system commands as root on the affected appliance node. Successful exploitation requires an administrative account with elevated privileges.

Affected Software

VendorProductVersion RangeStatus
KiteworksCore0 < 9.5.0affected
KiteworksCore9.5.0unaffected

Weaknesses

  • CWE-78: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

References