CVE-2026-102114: Kiteworks Core OS Command Injection
Published Sep 30, 2026
·Updated
A command injection vulnerability in Kiteworks could allow a high-privileged authenticated administrator to execute arbitrary operating-system commands as root on the affected appliance node. Successful exploitation requires an administrative account with elevated privileges.
Affected Software
1 affected component
Kiteworks Kiteworks Core OS
Event History
Sep 30, 2026
CVE Published
via MITRE·08:20 PM
Data Sourced
via MITRE·08:20 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this vulnerability?
Exploitation requires an authenticated Kiteworks administrative account with elevated privileges. It is not described as exploitable by unauthenticated users or lower-privileged accounts.
2
What level of access could an attacker obtain?
A successful attacker can execute arbitrary operating-system commands as root on the affected appliance node. This can impact confidentiality, integrity, and availability of that node.