Description
A system notification template on the Kiteworks appliance was rendered by a template engine that evaluated expressions contained in the stored template body. An authenticated System Administrator could potentially store a crafted template that executed operating-system commands on the appliance when the notification was next sent.
Published: 2026-09-30
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch or Mitigate
AI Analysis

Impact

A server‑side template injection flaw in Kiteworks Core allows an authenticated System Administrator to store a custom notification template containing executable expressions. When the notification is later dispatched, the template engine evaluates the malicious content, enabling arbitrary operating‑system command execution. This vulnerability is classified as CWE-1336 and can lead to full remote code execution on the appliance, compromising confidentiality, integrity, and availability of the system.

Affected Systems

The affected product is Kiteworks Core. No specific version ranges are listed in the advisory, so all released versions of Kiteworks Core that have not yet applied a vendor‑issued fix are at risk. The advisory does not provide detailed version information, so administrators should verify whether their deployment includes the flaw by confirming the applied patch level.

Risk and Exploitability

The CVSS score of 7.2 places this vulnerability in the medium‑to‑high severity range, indicating that an exploited instance can have a substantial impact. The EPSS score is not available, so the likelihood of exploitation remains uncertain, but the lack of KEV listing suggests no known widespread exploitation yet. Because the attack requires authenticated System Administrator privileges, the exploitation vector is limited to users with elevated access; however, internally compromised accounts or credentials stolen by attackers could still be leveraged to activate the flaw. Given the potential for arbitrary code execution, the risk to affected deployments is considered significant and warrants focused remediation.

Generated by OpenCVE AI on September 30, 2026 at 22:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy the vendor’s official patch for Kiteworks Core as soon as it becomes available.
  • Restrict the ability to modify notification templates to a minimal, trusted group of administrators and enforce strict access controls.
  • If a patch is not yet available, disable or remove the notification template feature to prevent execution of stored expressions.
  • Implement monitoring on the appliance for any unauthorized template changes and validate the integrity of configuration files.

Generated by OpenCVE AI on September 30, 2026 at 22:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Kiteworks
Kiteworks core
Vendors & Products Kiteworks
Kiteworks core

Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A system notification template on the Kiteworks appliance was rendered by a template engine that evaluated expressions contained in the stored template body. An authenticated System Administrator could potentially store a crafted template that executed operating-system commands on the appliance when the notification was next sent.
Title Kiteworks Core Remote Code Execution through Server-Side Template Injection
Weaknesses CWE-1336
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-10-01T15:28:05.497Z

Reserved: 2026-09-28T17:39:13.564Z

Link: CVE-2026-102142

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T21:17:03.027

Modified: 2026-10-01T16:17:33.380

Link: CVE-2026-102142

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T08:15:04Z

Weaknesses
  • CWE-1336

    Improper Neutralization of Special Elements Used in a Template Engine