Description
In multi-node deployments, an attacker who had already obtained code execution on one appliance node could submit a value through an internal cluster interface that was written into monitoring configuration on another node without sufficient validation, potentially allowing OS commands to be executed there. Execution was limited to an unprivileged service account on that node.
Published: 2026-09-30
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: Remote Command Execution with limited privileges via configuration injection
Action: Immediate Patch
AI Analysis

Impact

In a multi‑node deployment of Kiteworks, an attacker who has local code execution on one node can submit arbitrary configuration values to an internal cluster interface. These values are written to monitoring configuration on another node without proper validation, allowing OS commands to be executed under an unprivileged service account. The vulnerability is a form of configuration injection that can lead to further compromise or lateral movement within the cluster.

Affected Systems

The affected product is Kiteworks Core, any multi‑node deployment using the internal cluster interface. Version information is not provided in the advisory, so all current releases of the Core product could be impacted.

Risk and Exploitability

The CVSS score of 6.3 indicates a moderate severity. Because the attack requires existing code execution on a node and access to the internal cluster interface, it is not a null‑click vulnerability and its overall exploitation probability is moderate. The advisory notes that no KEV listing exists and the EPSS value is not available. Consequently, the threat is most pronounced when an attacker has already compromised a node in the cluster; no public exploit has been reported at this time.

Generated by OpenCVE AI on September 30, 2026 at 22:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch or update to the latest release of Kiteworks Core once available.
  • Restrict the internal cluster interface so that only trusted nodes and authenticated clients can submit configuration changes.
  • Enforce strict input validation on all configuration parameters to reject non‑shell‑command content and limit allowed values.

Generated by OpenCVE AI on September 30, 2026 at 22:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Kiteworks
Kiteworks core
Vendors & Products Kiteworks
Kiteworks core

Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description In multi-node deployments, an attacker who had already obtained code execution on one appliance node could submit a value through an internal cluster interface that was written into monitoring configuration on another node without sufficient validation, potentially allowing OS commands to be executed there. Execution was limited to an unprivileged service account on that node.
Title Kiteworks Core Command Execution through Configuration Injection
Weaknesses CWE-93
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-09-30T20:12:07.108Z

Reserved: 2026-09-28T17:39:13.563Z

Link: CVE-2026-102136

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T21:17:02.277

Modified: 2026-10-01T02:17:43.350

Link: CVE-2026-102136

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T06:00:13Z

Weaknesses
  • CWE-93

    Improper Neutralization of CRLF Sequences ('CRLF Injection')