Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 30 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A privilege escalation vulnerability in Kiteworks could have allowed an attacker who had already obtained code execution on one node of a clustered Kiteworks deployment to run operating system commands with elevated privileges on another node of the same cluster. Insufficient input validation in an internal cluster management function let attacker-supplied values reach a privileged execution context; exploitation requires existing access to a node in the cluster, and the affected function is not reachable from outside the cluster. | |
| Title | Kiteworks Core OS Command Injection | |
| Weaknesses | CWE-269 CWE-78 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2026-09-30T20:17:48.543Z
Reserved: 2026-09-28T17:39:13.562Z
Link: CVE-2026-102120
No data.
Status : Received
Published: 2026-09-30T21:17:00.057
Modified: 2026-09-30T21:17:00.057
Link: CVE-2026-102120
No data.
OpenCVE Enrichment
Updated: 2026-09-30T22:30:07Z