CVE-2026-102113: Kiteworks Core Local Privilege Escalation

Published Sep 30, 2026
·
Updated

A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root. A privileged routine did not safely handle a filesystem path that the lower-privileged account could influence, allowing the attacker to cause a root-owned operation to run arbitrary commands with the highest privileges. Exploitation requires existing local access to that service account.

Affected Software

1 affected component
Kiteworks Kiteworks Core

Event History

Sep 30, 2026
CVE Published
via MITRE·08:20 PM
Data Sourced
via MITRE·08:20 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to exploitation?

Only attackers who already have local code execution as an unprivileged backend service account on a Kiteworks appliance can exploit this issue. It is a local privilege-escalation vulnerability, not an unauthenticated remote entry point.

2

What access or capability does an attacker need?

The attacker needs existing local access to the affected backend service account and the ability to influence a filesystem path handled by a privileged routine. They can then cause a root-owned operation to execute arbitrary commands as root.

3

What is the likely impact after successful exploitation?

Successful exploitation gives the attacker root-level command execution on the appliance. This can compromise confidentiality, integrity, and availability of the affected system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203