Security Vulnerability in Multi-Node Deployments of Kiteworks Appliance
CVE-2026-102136
6.3MEDIUM
What is CVE-2026-102136?
In multi-node deployments of the Kiteworks appliance, a security issue exists where an attacker with code execution on one node can exploit an internal cluster interface. This allows them to manipulate monitoring configurations on another node without adequate validation checks. Consequently, this vulnerability enables the potential execution of OS commands on the target node, but only under the restrictions of an unprivileged service account.
Affected Version(s)
Core 0 < 9.5.1
Core 9.5.1
References
CVSS V3.1
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Icare, https://yeswehack.com/hunters/icare
Supr4s, https://yeswehack.com/hunters/Supr4s
wlayzz, https://yeswehack.com/hunters/wlayzz
truff, https://yeswehack.com/hunters/truff
