Command Injection Vulnerability in Kiteworks Core Affecting Service Accounts
CVE-2026-102133

6.6MEDIUM

Key Information:

Vendor

Kiteworks

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-102133?

A command injection vulnerability exists in Kiteworks Core's repository-connector feature, which fails to properly neutralize special characters in user-supplied paths. An authenticated system administrator can exploit this weakness by injecting additional commands, potentially leading to arbitrary file writes under the privileges of the associated service account. Successful exploitation also necessitates network egress to a system controlled by the attacker, allowing for further compromise. This vulnerability highlights the importance of proper input validation and security measures to prevent unauthorized command execution.

Affected Version(s)

Core 0 < 9.5.1

Core 9.5.1

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Icare, https://yeswehack.com/hunters/icare
Supr4s, https://yeswehack.com/hunters/Supr4s
wlayzz, https://yeswehack.com/hunters/wlayzz
truff, https://yeswehack.com/hunters/truff
.