CVE-2026-102118

Summary

A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an existing shell under a low-privileged service account to escalate to root privileges on the appliance.

Affected Software

VendorProductVersion RangeStatus
KiteworksCore0 < 9.5.0affected
KiteworksCore9.5.0unaffected

Weaknesses

  • CWE-59: CWE-59 Improper Link Resolution Before File Access ('Link Following')
  • CWE-250: CWE-250 Execution with Unnecessary Privileges

References