Privilege Escalation Vulnerability in Kiteworks
CVE-2026-102120
8.8HIGH
What is CVE-2026-102120?
A privilege escalation vulnerability exists within the Kiteworks platform that allows an attacker, who has already gained code execution on one node within a clustered environment, to escalate their privileges. This can result in the execution of operating system commands on another node within the same cluster. The root cause stems from inadequate input validation within an internal cluster management function, which permits attacker-controlled values to escalate their execution privileges. However, it is important to note that exploitation of this vulnerability necessitates prior access to one of the cluster nodes, making it inaccessible from external sources.
Affected Version(s)
Core 0 < 9.5.1
Core 9.5.1
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Icare, https://yeswehack.com/hunters/icare
Supr4s, https://yeswehack.com/hunters/Supr4s
wlayzz, https://yeswehack.com/hunters/wlayzz
truff, https://yeswehack.com/hunters/truff
