CVE-2026-102120
Received Received - Intake

Privilege Escalation in Kiteworks Clustered Deployment

Vulnerability report for CVE-2026-102120, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Description

A privilege escalation vulnerability in Kiteworks could have allowed an attacker who had already obtained code execution on one node of a clustered Kiteworks deployment to run operating system commands with elevated privileges on another node of the same cluster. Insufficient input validation in an internal cluster management function let attacker-supplied values reach a privileged execution context; exploitation requires existing access to a node in the cluster, and the affected function is not reachable from outside the cluster.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
kiteworks kiteworks *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a privilege escalation vulnerability in Kiteworks that allows an attacker with existing code execution on one node of a clustered deployment to run OS commands with higher privileges on another node in the same cluster. It occurs due to insufficient input validation in an internal cluster management function, enabling attacker-controlled values to reach a privileged execution context.

Detection Guidance

This vulnerability requires existing access to a node in the Kiteworks cluster and cannot be detected from outside the cluster. Check for unauthorized privilege escalation attempts within cluster nodes by monitoring logs for suspicious commands or unusual activity in privileged execution contexts.

Impact Analysis

If you use a Kiteworks clustered deployment, an attacker who already has access to one node could escalate their privileges to control other nodes in the cluster. This could lead to unauthorized access to sensitive data, system compromise, or further lateral movement within your network.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Organizations using Kiteworks clusters may face penalties, reputational damage, or legal consequences if this flaw is exploited to access protected data.

Mitigation Strategies

Apply vendor patches or updates for Kiteworks to address the insufficient input validation. Restrict access to cluster nodes to only authorized personnel and monitor internal cluster communications for signs of exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102120. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart