CVE-2026-102141
6.7
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:L
Summary
Two Kiteworks Core cluster-management operations did not validate file paths supplied to them, so an attacker holding root on one node of a cluster could write files as root onto another node and cause them to be executed there. Exploitation requires backend root access on a cluster node and a pending software patch present on the target node.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Kiteworks | Core | 0 < 9.5.1 | affected |
| Kiteworks | Core | 9.5.1 | unaffected |
Weaknesses
- CWE-73: CWE-73 External Control of File Name or Path
- CWE-269: CWE-269 Improper Privilege Management
References
- https://github.com/kiteworks/security-advisories/security/advisories/GHSA-m39v-w8fv-gf3m
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.