Privilege Escalation Vulnerability in Kiteworks by Kiteworks
CVE-2026-102113
7.8HIGH
What is CVE-2026-102113?
A privilege escalation vulnerability exists in Kiteworks, allowing an attacker with code execution as an unprivileged backend service account to escalate privileges to root. This occurs due to inadequate handling of a filesystem path by a privileged routine, which the lower-privileged account can influence. Consequently, an attacker can execute arbitrary commands with root privileges. Exploitation requires that the attacker already has local access to the service account, making it crucial for organizations to address this issue promptly.
Affected Version(s)
Core 0 < 9.5.0
Core 9.5.0
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Icare, https://yeswehack.com/hunters/icare
Supr4s, https://yeswehack.com/hunters/Supr4s
wlayzz, https://yeswehack.com/hunters/wlayzz
truff, https://yeswehack.com/hunters/truff
