Impact
A command injection flaw in Kiteworks Core enables an authenticated administrator with elevated privileges to execute arbitrary operating‑system commands as root on the appliance node. This vulnerability falls under CWE‑78 and permits an attacker to gain full system control, compromising confidentiality, integrity, and availability of the affected infrastructure.
Affected Systems
Kiteworks Core appliances are affected. No specific version information is provided in the advisory, so all deployed instances of the Core software should be considered vulnerable until confirmed otherwise.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, suggesting that no widespread exploitation has been observed yet. Successful exploitation requires a legitimate administrator account; therefore the attack vector is likely an authenticated session. An attacker who compromises an admin account or gains privileged credentials can execute commands with root capabilities, making this a critical condition to mitigate.
OpenCVE Enrichment