Kiteworks Core Command Execution through Configuration Injection
Summary
| CVE | CVE-2026-102136 |
|---|---|
| State | PUBLISHED |
| Assigner | cisa-cg |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-30 21:17:02 UTC |
| Updated | 2026-10-01 14:17:18 UTC |
| Description | In multi-node deployments, an attacker who had already obtained code execution on one appliance node could submit a value through an internal cluster interface that was written into monitoring configuration on another node without sufficient validation, potentially allowing OS commands to be executed there. Execution was limited to an unprivileged service account on that node. |
Risk And Classification
Primary CVSS: v3.1 6.3 MEDIUM from 9119a7d8-5eab-497f-8521-727c672e3725
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Problem Types: CWE-93 | CWE-93 CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 9119a7d8-5eab-497f-8521-727c672e3725 | Secondary | 6.3 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L |
| 3.1 | CNA | DECLARED | 6.3 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
ChangedConfidentiality
LowIntegrity
LowAvailability
LowCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json | 9119a7d8-5eab-497f-8521-727c672e3725 | raw.githubusercontent.com | |
| github.com/kiteworks/security-advisories/security/advisories/GHSA-rpxx-j... | 9119a7d8-5eab-497f-8521-727c672e3725 | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Icare, https://yeswehack.com/hunters/icare (en)
CNA: Supr4s, https://yeswehack.com/hunters/Supr4s (en)
CNA: wlayzz, https://yeswehack.com/hunters/wlayzz (en)
CNA: truff, https://yeswehack.com/hunters/truff (en)
There are currently no legacy QID mappings associated with this CVE.