Security Vulnerability in Multi-Node Deployments of Kiteworks Appliance
CVE-2026-102136

6.3MEDIUM

Key Information:

Vendor

Kiteworks

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-102136?

In multi-node deployments of the Kiteworks appliance, a security issue exists where an attacker with code execution on one node can exploit an internal cluster interface. This allows them to manipulate monitoring configurations on another node without adequate validation checks. Consequently, this vulnerability enables the potential execution of OS commands on the target node, but only under the restrictions of an unprivileged service account.

Affected Version(s)

Core 0 < 9.5.1

Core 9.5.1

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Icare, https://yeswehack.com/hunters/icare
Supr4s, https://yeswehack.com/hunters/Supr4s
wlayzz, https://yeswehack.com/hunters/wlayzz
truff, https://yeswehack.com/hunters/truff
.