CVE-2026-102118: Kiteworks Core before version 9.5.0 is vulnerable to Local Privilege Escalation
A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an existing shell under a low-privileged service account to escalate to root privileges on the appliance.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Kiteworks Coreto a version that resolves this vulnerability.Fixed in 9.5.0
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Kiteworks Core deployments running a version before 9.5.0 are affected. Exploitation requires local access to the appliance through an existing shell under a low-privileged service account.
What level of access can an attacker gain?
An attacker who meets the local access prerequisite could escalate from a low-privileged service account to root privileges on the appliance.
What is the remediation?
Upgrade Kiteworks Core to version 9.5.0 or later. The provided data does not specify compensating controls for systems that cannot be patched immediately.