CVE-2026-102133

MEDIUM Status: Received

CVSS Scores

CVSS v3.x Base Score
6.6
MEDIUM

Description

An optional, separately licensed repository-connector feature in Kiteworks Core did not neutralize special characters in a user-supplied path before passing it to an external command. An authenticated system administrator could inject additional commands and write arbitrary content to files owned by the service account running the connector, enabling code execution in that account's context; exploitation additionally requires network egress from the appliance to a system under the attacker's control.

Published
September 30, 2026 9:17 PM
Last Modified
September 30, 2026 9:17 PM
Source
9119a7d8-5eab-497f-8521-727c672e3725

Weaknesses (CWE)

CWE-77

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.