CVE-2026-102133Medium· 6.6▾ SunlitAn optional, separately licensed repository-connector feature in Kiteworks Core did not neutralize special characters in a user-supplied path before passing it to an external command. An authenticated system administrator could inject ad…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 36.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
An optional, separately licensed repository-connector feature in Kiteworks Core did not neutralize special characters in a user-supplied path before passing it to an external command. An authenticated system administrator could inject additional commands and write arbitrary content to files owned by the service account running the connector, enabling code execution in that account's context; exploitation additionally requires network egress from the appliance to a system under the attacker's control.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102145Medium· 6.6An authenticated administrator could cause the server to issue requests to, and interact with, internal network services that are not meant to be reachable through this interface
CVE-2026-102147Critical· 9.3A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauthenticated attacker to store crafted content that later executes arbitrary JavaScript in the authenticated session of an administrator who views the affec…
CVE-2026-102141Medium· 6.7Two Kiteworks Core cluster-management operations did not validate file paths supplied to them, so an attacker holding root on one node of a cluster could write files as root onto another node and cause them to be executed there
CVE-2026-102142High· 7.2A system notification template on the Kiteworks appliance was rendered by a template engine that evaluated expressions contained in the stored template body
CVE-2026-102138Low· 3.3An authenticated administrator on a node with an optional, separately licensed gateway role enabled could supply a connector URL that the server retrieved without sufficient validation of its scheme or destination, causing the server to …
CVE-2026-102140Medium· 4.9An authenticated administrator could initiate an administrative import using a file whose contents were not fully verified, because the import validated only the file's header rather than the complete file