CVE-2026-102117: Kiteworks Core Remote Code Execution
On deployments where the remote-support capability is licensed and enabled, an authenticated System Administrator who also possessed the key protecting the submitted data could redirect the underlying system's outbound support connection to a destination of their choosing. That destination could then have operating-system commands executed on the node and receive their output, potentially resulting in remote code execution with the privileges of a local service account.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
Only deployments where the remote-support capability is both licensed and enabled are described as affected. Exploitation also requires an authenticated System Administrator who possesses the key protecting the submitted data.
What access and conditions does an attacker need?
The attacker needs System Administrator authentication and the key protecting submitted data. They can then redirect the system's outbound support connection to an attacker-controlled destination.
What is the likely impact of successful exploitation?
The attacker-controlled destination can cause operating-system commands to run on the affected node and receive their output. Commands may execute with the privileges of a local service account.