Privilege Escalation Vulnerability in Kiteworks
CVE-2026-102120

8.8HIGH

Key Information:

Vendor

Kiteworks

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-102120?

A privilege escalation vulnerability exists within the Kiteworks platform that allows an attacker, who has already gained code execution on one node within a clustered environment, to escalate their privileges. This can result in the execution of operating system commands on another node within the same cluster. The root cause stems from inadequate input validation within an internal cluster management function, which permits attacker-controlled values to escalate their execution privileges. However, it is important to note that exploitation of this vulnerability necessitates prior access to one of the cluster nodes, making it inaccessible from external sources.

Affected Version(s)

Core 0 < 9.5.1

Core 9.5.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Icare, https://yeswehack.com/hunters/icare
Supr4s, https://yeswehack.com/hunters/Supr4s
wlayzz, https://yeswehack.com/hunters/wlayzz
truff, https://yeswehack.com/hunters/truff
.