---
id: CVE-2026-102125
title: >-
  The sandbox that isolates document conversion on a Kiteworks appliance did not
  fully confine the code running inside it
summary: >-
  The sandbox that isolates document conversion on a Kiteworks appliance did not
  fully confine the code running inside it. Code already executing within that
  sandbox could potentially escape its confinement and act with the privileges
  of t…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-653
  - CWE-668
vendor: Kiteworks
product: Core
affected:
  - Core < 9.5.0
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:17:00.813'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102125'
references:
  - url: >-
      https://github.com/kiteworks/security-advisories/security/advisories/GHSA-58j2-hj9r-c258
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T21:25:07.830Z'
---

## Overview

The sandbox that isolates document conversion on a Kiteworks appliance did not fully confine the code running inside it. Code already executing within that sandbox could potentially escape its confinement and act with the privileges of the service account that runs the application, which could allow an attacker in that position to read or modify application data and configuration, or to disrupt the service on the affected appliance.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
