Command Execution Vulnerability in Kiteworks Private Data Network
CVE-2026-28269

5.9MEDIUM

Key Information:

Vendor

Kiteworks

Vendor
CVE Published:
26 February 2026

What is CVE-2026-28269?

Kiteworks, a Private Data Network, has a command execution vulnerability affecting versions prior to 9.2.0. Authenticated users can exploit this flaw to redirect command output to arbitrary file locations, potentially overwriting critical system files and escalating access privileges. The issue has been addressed in version 9.2.0 with a patch to enhance security against such exploits.

Affected Version(s)

security-advisories < 9.2.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.