Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 30 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An optional, separately licensed repository-connector feature in Kiteworks Core did not neutralize special characters in a user-supplied path before passing it to an external command. An authenticated system administrator could inject additional commands and write arbitrary content to files owned by the service account running the connector, enabling code execution in that account's context; exploitation additionally requires network egress from the appliance to a system under the attacker's control. | |
| Title | Kiteworks Core Arbitrary File Write through Command Injection | |
| Weaknesses | CWE-77 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2026-09-30T20:13:09.677Z
Reserved: 2026-09-28T17:39:13.563Z
Link: CVE-2026-102133
No data.
Status : Received
Published: 2026-09-30T21:17:01.910
Modified: 2026-09-30T21:17:01.910
Link: CVE-2026-102133
No data.
OpenCVE Enrichment
Updated: 2026-09-30T22:15:14Z
-
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')