Description
An optional, separately licensed repository-connector feature in Kiteworks Core did not neutralize special characters in a user-supplied path before passing it to an external command. An authenticated system administrator could inject additional commands and write arbitrary content to files owned by the service account running the connector, enabling code execution in that account's context; exploitation additionally requires network egress from the appliance to a system under the attacker's control.
Published: 2026-09-30
Score: 6.6 Medium
EPSS: n/a
KEV: No
Impact: Remote Code Execution via Command Injection
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is an arbitrary file write mistake caused by the repository‑connector feature of Kiteworks Core. It allows an authenticated system administrator to supply a file path that is not sanitized before being given to a shell command. The flaw can be exploited to write any content to files owned by the connector’s service account, opening the door for execution of arbitrary code in that account’s context. The weakness is a classic command injection situation described by CWE‑77.

Affected Systems

Kiteworks Core contains the vulnerable connector. No specific version list is supplied, so any deployment that has the repository‑connector enabled and applies a license that activates the feature is at risk. The vulnerability exists in the component that handles user‑supplied paths for external commands.

Risk and Exploitability

The CVSS score of 6.6 indicates moderate severity. There is no EPSS data available, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog. An attacker must be an authenticated system administrator and must have network egress from the appliance to a system under the attacker’s control to receive the injected file. The attack vector is inferred: an attacker must already have administrative access and an outbound channel to a controlled host to supply the payload path. If these conditions are met, code execution runs as the connector service account, granting powerful system capabilities.

Generated by OpenCVE AI on September 30, 2026 at 22:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official Kiteworks Core patch issued in the security advisory
  • If a patch is not yet available, disable the repository‑connector feature until an update is released
  • Ensure that the appliance’s network egress is restricted so that even an authenticated administrator cannot send commands to a remote system under attacker control

Generated by OpenCVE AI on September 30, 2026 at 22:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Kiteworks
Kiteworks core
Vendors & Products Kiteworks
Kiteworks core

Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description An optional, separately licensed repository-connector feature in Kiteworks Core did not neutralize special characters in a user-supplied path before passing it to an external command. An authenticated system administrator could inject additional commands and write arbitrary content to files owned by the service account running the connector, enabling code execution in that account's context; exploitation additionally requires network egress from the appliance to a system under the attacker's control.
Title Kiteworks Core Arbitrary File Write through Command Injection
Weaknesses CWE-77
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-09-30T20:13:09.677Z

Reserved: 2026-09-28T17:39:13.563Z

Link: CVE-2026-102133

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T21:17:01.910

Modified: 2026-10-01T02:17:43.350

Link: CVE-2026-102133

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T06:00:13Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')