Description
A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an existing shell under a low-privileged service account to escalate to root privileges on the appliance.
Published: 2026-09-30
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Local Privilege Escalation
Action: Patch ASAP
AI Analysis

Impact

A local privilege escalation issue was discovered in Kiteworks Core versions prior to 9.5.0. An attacker who can spawn a shell under a low‑privileged service account could exploit the flaw to execute code with root privileges on the appliance. This elevation of privilege can lead to full system compromise, including unauthorized data access, modification, or disruption. The vulnerability is associated with CWE‑250 (Execution as Different User) and CWE‑59 (Dereferencing a Null Pointer) and allows an attacker to gain control of the entire environment.

Affected Systems

The affected product is Kiteworks Core for all platforms. Versions older than 9.5.0 are impacted; upgrades to 9.5.0 or later contain the fix.

Risk and Exploitability

The CVSS score is 7.8, indicating high severity, but the EPSS score is not available so the exact current exploitation likelihood cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Attackers require local access and a pre‑existing shell under a low‑privileged account, making it a local attack. If successfully exploited, the attacker can execute arbitrary commands as root, effectively controlling the entire appliance.

Generated by OpenCVE AI on September 30, 2026 at 21:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Kiteworks Core to version 9.5.0 or newer
  • Reinforce service account entitlements by disabling unnecessary local shell capabilities and applying the principle of least privilege
  • Configure audit logging and intrusion detection to monitor for privilege escalation attempts and anomalous system activity

Generated by OpenCVE AI on September 30, 2026 at 21:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an existing shell under a low-privileged service account to escalate to root privileges on the appliance.
Title Kiteworks Core before version 9.5.0 is vulnerable to Local Privilege Escalation
Weaknesses CWE-250
CWE-59
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-09-30T20:18:21.236Z

Reserved: 2026-09-28T17:39:13.562Z

Link: CVE-2026-102118

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T21:16:59.707

Modified: 2026-09-30T21:16:59.707

Link: CVE-2026-102118

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T22:00:16Z

Weaknesses
  • CWE-250

    Execution with Unnecessary Privileges

  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')