Description
Two Kiteworks Core cluster-management operations did not validate file paths supplied to them, so an attacker holding root on one node of a cluster could write files as root onto another node and cause them to be executed there. Exploitation requires backend root access on a cluster node and a pending software patch present on the target node.
Published: 2026-09-30
Score: 6.7 Medium
EPSS: n/a
KEV: No
Impact: Privilege escalation and arbitrary file execution within a Kiteworks Core cluster
Action: Immediate Patch
AI Analysis

Impact

Two cluster‑management operations in Kiteworks Core lacked validation of file paths supplied by users. An attacker who already holds root or administrative access to one node can supply arbitrary paths and write files as root onto another node. Those files can then be executed, giving the attacker the ability to run arbitrary code on additional nodes and effectively elevate privileges within the cluster. This flaw represents an elevation of privilege and path‑traversal weakness.

Affected Systems

The vulnerability affects the Kiteworks Core product. No specific version numbers are listed, so any installation of Kiteworks Core that has not applied the latest patch to enforce path validation is potentially vulnerable. All nodes in a cluster running an unpatched instance can be impacted.

Risk and Exploitability

The CVSS score of 6.7 indicates moderate severity. The vulnerability is not listed in CISA KEV and the EPSS score is not available, implying limited public exploitation data. Exploitation requires the attacker to already have root or administrative control of a cluster node and the target node must still be running a version of the software that lacks the patch. Therefore the attack surface is largely internal or relies on compromise of an existing node, and remote exploitation from the public internet is unlikely unless the attacker can first gain such privileged access.

Generated by OpenCVE AI on September 30, 2026 at 22:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy Kiteworks Core's latest security patch that validates file paths in cluster‑management operations.
  • Verify that every cluster node is running the patched version and that file write operations are properly validated before execution.
  • Restrict root and administrative access to cluster nodes; enforce least privilege and separate credentials for normal operation.
  • If the patch cannot be applied immediately, isolate unpatched nodes from the cluster network and disable external exposure of cluster‑management APIs.

Generated by OpenCVE AI on September 30, 2026 at 22:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Kiteworks
Kiteworks core
Vendors & Products Kiteworks
Kiteworks core

Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description Two Kiteworks Core cluster-management operations did not validate file paths supplied to them, so an attacker holding root on one node of a cluster could write files as root onto another node and cause them to be executed there. Exploitation requires backend root access on a cluster node and a pending software patch present on the target node.
Title Kiteworks Core Privilege Escalation through External Control of File Name or Path
Weaknesses CWE-269
CWE-73
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-09-30T20:10:55.599Z

Reserved: 2026-09-28T17:39:13.564Z

Link: CVE-2026-102141

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T21:17:02.903

Modified: 2026-10-01T02:17:43.350

Link: CVE-2026-102141

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T06:00:13Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-73

    External Control of File Name or Path