CVE-2026-102118
Received Received - Intake

Local Privilege Escalation in Kiteworks Appliance

Vulnerability report for CVE-2026-102118, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Description

A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an existing shell under a low-privileged service account to escalate to root privileges on the appliance.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
kiteworks kiteworks *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-250 The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
CWE-59 The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a local privilege escalation vulnerability in Kiteworks software. It allows an attacker who already has a low-privileged shell access to escalate their privileges to root level on the affected appliance.

Impact Analysis

If exploited, this vulnerability could allow an attacker to gain full control over the Kiteworks appliance. This could lead to unauthorized access to sensitive data, system manipulation, or further network compromise from the elevated privileges.

Compliance Impact

This vulnerability could allow unauthorized privilege escalation to root access, potentially compromising sensitive data confidentiality and integrity. Such breaches may violate compliance requirements under GDPR (data protection) and HIPAA (health information security) by enabling unauthorized access to protected data.

Mitigation Strategies

Apply the latest security patches or updates provided by Kiteworks to address the local privilege escalation vulnerability. Restrict access to low-privileged service accounts and monitor for unusual privilege escalation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102118. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart