๐Ÿ” CVE Alert

CVE-2026-102096

HIGH 7.2

Kiteworks Core OS command injection

CVSS Score
7.2
EPSS Score
0.0%
EPSS Percentile
0th

Kiteworks Core before version 9.5.0 is vulnerable to OS Command Injection that allows an authenticated administrator to upload a configuration package whose contents were not sufficiently validated before being processed. A crafted package could cause the underlying system to execute arbitrary operating-system commands, potentially with elevated privileges, on the affected appliance.

CWE CWE-78
Vendor kiteworks
Product core
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for kiteworks core

Be the first to know when new high vulnerabilities affecting kiteworks core are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Kiteworks / Core
0 < 9.5.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/kiteworks/security-advisories/security/advisories/GHSA-c3wx-5mx6-2qpg raw.githubusercontent.com: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json

Credits

Supr4s, https://yeswehack.com/hunters/supr4s Icare, https://yeswehack.com/hunters/icare