CVE-2026-102133
Received Received - Intake

Command Injection in Kiteworks Core

Vulnerability report for CVE-2026-102133, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Description

An optional, separately licensed repository-connector feature in Kiteworks Core did not neutralize special characters in a user-supplied path before passing it to an external command. An authenticated system administrator could inject additional commands and write arbitrary content to files owned by the service account running the connector, enabling code execution in that account's context; exploitation additionally requires network egress from the appliance to a system under the attacker's control.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
kiteworks core *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-77 The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in Kiteworks Core's repository-connector feature. It allows an authenticated system administrator to inject commands through a user-supplied path that isn't properly sanitized before being passed to an external command. This could let the attacker write arbitrary files to the service account's directory and execute code within that account's permissions.

Impact Analysis

If exploited, this vulnerability could allow an attacker with admin access to execute arbitrary code on the system running Kiteworks Core. This could lead to data breaches, unauthorized access to sensitive information, or further compromise of the network if the service account has elevated privileges.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, which would violate compliance requirements under GDPR (data protection) and HIPAA (health information privacy). Organizations using Kiteworks Core may face regulatory penalties or loss of certification if this flaw is exploited.

Mitigation Strategies

Disable the repository-connector feature if not in use. Apply vendor patches or updates to neutralize special characters in user-supplied paths. Restrict network egress from the appliance to prevent unauthorized connections. Review file permissions for the service account running the connector.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102133. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart