Description
A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root and run arbitrary commands with the highest privileges. Exploitation requires existing local access to that service account.
Published: 2026-09-30
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Local Privilege Escalation to root
Action: Patch if available
AI Analysis

Impact

A back‑end service running under an unprivileged account on a Kiteworks appliance can be coerced by an attacker who has already executed code locally into elevating privileges to root and executing any arbitrary command. The flaw is a classic privilege management weakness compounded by an operating system command injection vulnerability, allowing the attacker to gain full control over the system. This gives an attacker full confidentiality, integrity, and availability compromise of the compromised appliance.

Affected Systems

Kiteworks Core – the professional file‑sharing and collaboration appliance. No specific version information was provided in the available data, so all installations of the Core component are potentially affected until a vendor patch is issued.

Risk and Exploitability

The CVSS base score of 7.8 indicates a high severity vulnerability. The EPSS score is not available, so the likelihood of exploitation cannot be quantified, yet the vulnerability is not listed in the CISA KEV catalog. The attack requires local access to the backend service account that is already running code; once such local code execution is achieved, the escalation can be completed with no further external interaction.

Generated by OpenCVE AI on September 30, 2026 at 22:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch or upgrade to the latest Kiteworks Core release once it is available
  • If a patch is not yet released, restrict local network access to the backend service account and ensure it operates with the minimal privileges necessary
  • Monitor system logs for suspicious command execution or privilege‑escalation attempts

Generated by OpenCVE AI on September 30, 2026 at 22:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root and run arbitrary commands with the highest privileges. Exploitation requires existing local access to that service account.
Title Kiteworks Core Local Privilege Escalation
Weaknesses CWE-269
CWE-78
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-09-30T20:20:59.159Z

Reserved: 2026-09-28T17:39:13.562Z

Link: CVE-2026-102112

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T21:16:58.267

Modified: 2026-09-30T21:16:58.267

Link: CVE-2026-102112

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T22:30:07Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')