Description
Kiteworks Core before version 9.5.0 is vulnerable to Arbitrary File Write. An improper restriction of a user-supplied file path in a Kiteworks administrative export feature could allow an authenticated administrator to write a file to an arbitrary location on the underlying host, potentially leading to command execution on the appliance. Exploitation requires an existing, authenticated administrative account with access to the affected export function.
Published: 2026-09-30
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Write
Action: Patch
AI Analysis

Impact

Kiteworks Core before version 9.5.0 allows an authenticated administrator to write a file to an arbitrary location on the underlying host through an administrative export feature that does not properly restrict the supplied file path. This flaw can lead to command execution on the appliance if an attacker can supply a payload that the host interprets as executable code. The vulnerability is an instance of path traversal (CWE‑22).

Affected Systems

The vulnerability affects Kiteworks Core, with all releases prior to 9.5.0 being susceptible. Systems running these versions without updated patches are at risk.

Risk and Exploitability

The CVSS v3 score of 7.2 indicates a high severity. EPSS data is not available, and the vulnerability is currently not listed in CISA’s KEV catalog. Exfiltration requires an authenticated administrative account with access to the export function, making the threat primarily internal or from compromised credentials. If exploited, the attacker can gain file write rights that may lead to remote code execution on the appliance.

Generated by OpenCVE AI on September 30, 2026 at 23:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Kiteworks Core update (version 9.5.0 or newer) to address the path traversal flaw.
  • Implement strict input validation to sanitize any user‑supplied file paths in the export feature, ensuring only approved directories are writable (CWE‑22 path traversal).
  • Restrict administrative access to the export endpoint, limiting the feature to essential users and disabling it via configuration if not required.

Generated by OpenCVE AI on September 30, 2026 at 23:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Kiteworks
Kiteworks core
Vendors & Products Kiteworks
Kiteworks core

Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description Kiteworks Core before version 9.5.0 is vulnerable to Arbitrary File Write. An improper restriction of a user-supplied file path in a Kiteworks administrative export feature could allow an authenticated administrator to write a file to an arbitrary location on the underlying host, potentially leading to command execution on the appliance. Exploitation requires an existing, authenticated administrative account with access to the affected export function.
Title Kiteworks Core arbitrary file write
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-10-01T13:37:08.818Z

Reserved: 2026-09-28T17:39:13.561Z

Link: CVE-2026-102099

cve-icon Vulnrichment

Updated: 2026-10-01T13:32:31.055Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T21:16:56.630

Modified: 2026-10-01T14:17:13.673

Link: CVE-2026-102099

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T08:15:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')