Impact
A server‑side template injection flaw in Kiteworks Core allows an authenticated System Administrator to store a custom notification template containing executable expressions. When the notification is later dispatched, the template engine evaluates the malicious content, enabling arbitrary operating‑system command execution. This vulnerability is classified as CWE-1336 and can lead to full remote code execution on the appliance, compromising confidentiality, integrity, and availability of the system.
Affected Systems
The affected product is Kiteworks Core. No specific version ranges are listed in the advisory, so all released versions of Kiteworks Core that have not yet applied a vendor‑issued fix are at risk. The advisory does not provide detailed version information, so administrators should verify whether their deployment includes the flaw by confirming the applied patch level.
Risk and Exploitability
The CVSS score of 7.2 places this vulnerability in the medium‑to‑high severity range, indicating that an exploited instance can have a substantial impact. The EPSS score is not available, so the likelihood of exploitation remains uncertain, but the lack of KEV listing suggests no known widespread exploitation yet. Because the attack requires authenticated System Administrator privileges, the exploitation vector is limited to users with elevated access; however, internally compromised accounts or credentials stolen by attackers could still be leveraged to activate the flaw. Given the potential for arbitrary code execution, the risk to affected deployments is considered significant and warrants focused remediation.
OpenCVE Enrichment