Impact
In a multi‑node deployment of Kiteworks, an attacker who has local code execution on one node can submit arbitrary configuration values to an internal cluster interface. These values are written to monitoring configuration on another node without proper validation, allowing OS commands to be executed under an unprivileged service account. The vulnerability is a form of configuration injection that can lead to further compromise or lateral movement within the cluster.
Affected Systems
The affected product is Kiteworks Core, any multi‑node deployment using the internal cluster interface. Version information is not provided in the advisory, so all current releases of the Core product could be impacted.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate severity. Because the attack requires existing code execution on a node and access to the internal cluster interface, it is not a null‑click vulnerability and its overall exploitation probability is moderate. The advisory notes that no KEV listing exists and the EPSS value is not available. Consequently, the threat is most pronounced when an attacker has already compromised a node in the cluster; no public exploit has been reported at this time.
OpenCVE Enrichment