Impact
Two cluster‑management operations in Kiteworks Core lacked validation of file paths supplied by users. An attacker who already holds root or administrative access to one node can supply arbitrary paths and write files as root onto another node. Those files can then be executed, giving the attacker the ability to run arbitrary code on additional nodes and effectively elevate privileges within the cluster. This flaw represents an elevation of privilege and path‑traversal weakness.
Affected Systems
The vulnerability affects the Kiteworks Core product. No specific version numbers are listed, so any installation of Kiteworks Core that has not applied the latest patch to enforce path validation is potentially vulnerable. All nodes in a cluster running an unpatched instance can be impacted.
Risk and Exploitability
The CVSS score of 6.7 indicates moderate severity. The vulnerability is not listed in CISA KEV and the EPSS score is not available, implying limited public exploitation data. Exploitation requires the attacker to already have root or administrative control of a cluster node and the target node must still be running a version of the software that lacks the patch. Therefore the attack surface is largely internal or relies on compromise of an existing node, and remote exploitation from the public internet is unlikely unless the attacker can first gain such privileged access.
OpenCVE Enrichment