No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 01 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 01 Oct 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kiteworks
Kiteworks core |
|
| Vendors & Products |
Kiteworks
Kiteworks core |
Wed, 30 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An optional, separately licensed repository-connector feature in Kiteworks Core did not neutralize special characters in a user-supplied path before passing it to an external command. An authenticated system administrator could inject additional commands and write arbitrary content to files owned by the service account running the connector, enabling code execution in that account's context; exploitation additionally requires network egress from the appliance to a system under the attacker's control. | |
| Title | Kiteworks Core Arbitrary File Write through Command Injection | |
| Weaknesses | CWE-77 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2026-10-01T13:37:06.177Z
Reserved: 2026-09-28T17:39:13.563Z
Link: CVE-2026-102133
Updated: 2026-10-01T13:32:09.940Z
Status : Awaiting Analysis
Published: 2026-09-30T21:17:01.910
Modified: 2026-10-01T14:17:17.753
Link: CVE-2026-102133
No data.
OpenCVE Enrichment
Updated: 2026-10-01T06:00:13Z