Command Injection Vulnerability in Kiteworks Core Affecting Service Accounts
CVE-2026-102133
6.6MEDIUM
What is CVE-2026-102133?
A command injection vulnerability exists in Kiteworks Core's repository-connector feature, which fails to properly neutralize special characters in user-supplied paths. An authenticated system administrator can exploit this weakness by injecting additional commands, potentially leading to arbitrary file writes under the privileges of the associated service account. Successful exploitation also necessitates network egress to a system controlled by the attacker, allowing for further compromise. This vulnerability highlights the importance of proper input validation and security measures to prevent unauthorized command execution.
Affected Version(s)
Core 0 < 9.5.1
Core 9.5.1
References
CVSS V3.1
Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Icare, https://yeswehack.com/hunters/icare
Supr4s, https://yeswehack.com/hunters/Supr4s
wlayzz, https://yeswehack.com/hunters/wlayzz
truff, https://yeswehack.com/hunters/truff
