CVE-2026-102141

MEDIUM Status: Received

CVSS Scores

CVSS v3.x Base Score
6.7
MEDIUM

Description

Two Kiteworks Core cluster-management operations did not validate file paths supplied to them, so an attacker holding root on one node of a cluster could write files as root onto another node and cause them to be executed there. Exploitation requires backend root access on a cluster node and a pending software patch present on the target node.

Published
September 30, 2026 9:17 PM
Last Modified
September 30, 2026 9:17 PM
Source
9119a7d8-5eab-497f-8521-727c672e3725

Weaknesses (CWE)

CWE-73 CWE-269

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.