---
id: CVE-2026-102112
title: >-
  A privilege escalation vulnerability in Kiteworks could allow an attacker who
  has already obtained code execution as an unprivileged backend service account
  on the appliance to escalate to root and run arbitrary commands with the
  highest…
summary: >-
  A privilege escalation vulnerability in Kiteworks could allow an attacker who
  has already obtained code execution as an unprivileged backend service account
  on the appliance to escalate to root and run arbitrary commands with the
  highest…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
  - CWE-269
vendor: Kiteworks
product: Core
affected:
  - Core < 9.5.0
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:16:58.267'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102112'
references:
  - url: >-
      https://github.com/kiteworks/security-advisories/security/advisories/GHSA-658c-86vw-g9hf
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T21:25:07.826Z'
---

## Overview

A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root and run arbitrary commands with the highest privileges. Exploitation requires existing local access to that service account.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
