Privilege Escalation Vulnerability in Kiteworks by Kiteworks
CVE-2026-102113

7.8HIGH

Key Information:

Vendor

Kiteworks

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-102113?

A privilege escalation vulnerability exists in Kiteworks, allowing an attacker with code execution as an unprivileged backend service account to escalate privileges to root. This occurs due to inadequate handling of a filesystem path by a privileged routine, which the lower-privileged account can influence. Consequently, an attacker can execute arbitrary commands with root privileges. Exploitation requires that the attacker already has local access to the service account, making it crucial for organizations to address this issue promptly.

Affected Version(s)

Core 0 < 9.5.0

Core 9.5.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Icare, https://yeswehack.com/hunters/icare
Supr4s, https://yeswehack.com/hunters/Supr4s
wlayzz, https://yeswehack.com/hunters/wlayzz
truff, https://yeswehack.com/hunters/truff
.