Description
On deployments where the remote-support capability is licensed and enabled, an authenticated System Administrator who also possessed the key protecting the submitted data could redirect the underlying system's outbound support connection to a destination of their choosing. That destination could then have operating-system commands executed on the node and receive their output, potentially resulting in remote code execution with the privileges of a local service account.
Published: 2026-09-30
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

In environments where the remote-support feature is licensed and enabled, the flaw allows an authenticated System Administrator who also holds the encryption key for transmitted data to hijack the defecting system’s outbound support channel to any destination chosen by the attacker. This can result in the execution of operating‑system commands on the target node and the retrieval of command output, effectively enabling remote code execution with the privileges of a local service account. The weakness is a combination of improper remote access control (CWE‑807) and misuse of privileged credentials (CWE‑940).

Affected Systems

The vulnerable product is Kiteworks Core. No specific version information is provided, but the issue applies to all deployments that have the remote-support capability licensed and enabled.

Risk and Exploitability

The CVSS score is 7.2, indicating a high level of severity. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog. Because the exploit requires authenticated access to a System Administrator account and possession of the support key, the attack vector is likely limited to insider or compromised administrator credentials. Given the high severity and the potential for full system compromise, organizations should treat this as a critical risk.

Generated by OpenCVE AI on September 30, 2026 at 21:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor’s patch or upgrade to the latest version of Kiteworks Core that addresses the remote-support control flaw
  • If a patch is not yet available, disable the remote-support capability or remove the licensed support option from the deployment
  • Ensure that only trusted, least‑privilege accounts have System Administrator access and that the key protecting transmitted data is protected with strong, multi‑factor authentication
  • Monitor outbound connections from the system for unexpected destinations and audit command execution logs for signs of exploitation

Generated by OpenCVE AI on September 30, 2026 at 21:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description On deployments where the remote-support capability is licensed and enabled, an authenticated System Administrator who also possessed the key protecting the submitted data could redirect the underlying system's outbound support connection to a destination of their choosing. That destination could then have operating-system commands executed on the node and receive their output, potentially resulting in remote code execution with the privileges of a local service account.
Title Kiteworks Core Remote Code Execution
Weaknesses CWE-807
CWE-940
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-09-30T20:19:02.903Z

Reserved: 2026-09-28T17:39:13.562Z

Link: CVE-2026-102117

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T21:16:59.533

Modified: 2026-09-30T21:16:59.533

Link: CVE-2026-102117

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T22:00:16Z

Weaknesses
  • CWE-807

    Reliance on Untrusted Inputs in a Security Decision

  • CWE-940

    Improper Verification of Source of a Communication Channel