CVE-2026-102113: Kiteworks Core Local Privilege Escalation
A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root. A privileged routine did not safely handle a filesystem path that the lower-privileged account could influence, allowing the attacker to cause a root-owned operation to run arbitrary commands with the highest privileges. Exploitation requires existing local access to that service account.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Only attackers who already have local code execution as an unprivileged backend service account on a Kiteworks appliance can exploit this issue. It is a local privilege-escalation vulnerability, not an unauthenticated remote entry point.
What access or capability does an attacker need?
The attacker needs existing local access to the affected backend service account and the ability to influence a filesystem path handled by a privileged routine. They can then cause a root-owned operation to execute arbitrary commands as root.
What is the likely impact after successful exploitation?
Successful exploitation gives the attacker root-level command execution on the appliance. This can compromise confidentiality, integrity, and availability of the affected system.