{"api_version":"1","generated_at":"2026-10-01T15:03:19+00:00","cve":"CVE-2026-102136","urls":{"html":"https://cve.report/CVE-2026-102136","api":"https://cve.report/api/cve/CVE-2026-102136.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-102136","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-102136"},"summary":{"title":"Kiteworks Core Command Execution through Configuration Injection","description":"In multi-node deployments, an attacker who had already obtained code execution on one appliance node could submit a value through an internal cluster interface that was written into monitoring configuration on another node without sufficient validation, potentially allowing OS commands to be executed there. Execution was limited to an unprivileged service account on that node.","state":"PUBLISHED","assigner":"cisa-cg","published_at":"2026-09-30 21:17:02","updated_at":"2026-10-01 14:17:18"},"problem_types":["CWE-93","CWE-93 CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')"],"metrics":[{"version":"3.1","source":"9119a7d8-5eab-497f-8521-727c672e3725","type":"Secondary","score":"6.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"6.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L","data":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"LOW","baseScore":6.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L","version":"3.1"}}],"references":[{"url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json","name":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json","refsource":"9119a7d8-5eab-497f-8521-727c672e3725","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/kiteworks/security-advisories/security/advisories/GHSA-rpxx-jm93-w5j7","name":"https://github.com/kiteworks/security-advisories/security/advisories/GHSA-rpxx-jm93-w5j7","refsource":"9119a7d8-5eab-497f-8521-727c672e3725","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-102136","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102136","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Kiteworks","product":"Core","version":"affected 9.5.1 custom","platforms":[]},{"source":"CNA","vendor":"Kiteworks","product":"Core","version":"unaffected 9.5.1","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Icare, https://yeswehack.com/hunters/icare","lang":"en"},{"source":"CNA","value":"Supr4s, https://yeswehack.com/hunters/Supr4s","lang":"en"},{"source":"CNA","value":"wlayzz, https://yeswehack.com/hunters/wlayzz","lang":"en"},{"source":"CNA","value":"truff, https://yeswehack.com/hunters/truff","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-102136","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-10-01T13:24:21.585395Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-10-01T13:37:06.915Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unknown","product":"Core","vendor":"Kiteworks","versions":[{"lessThan":"9.5.1","status":"affected","version":"0","versionType":"custom"},{"status":"unaffected","version":"9.5.1"}]}],"credits":[{"lang":"en","value":"Icare, https://yeswehack.com/hunters/icare"},{"lang":"en","value":"Supr4s, https://yeswehack.com/hunters/Supr4s"},{"lang":"en","value":"wlayzz, https://yeswehack.com/hunters/wlayzz"},{"lang":"en","value":"truff, https://yeswehack.com/hunters/truff"}],"datePublic":"2026-09-30T00:00:00.000Z","descriptions":[{"lang":"en","value":"In multi-node deployments, an attacker who had already obtained code execution on one appliance node could submit a value through an internal cluster interface that was written into monitoring configuration on another node without sufficient validation, potentially allowing OS commands to be executed there. Execution was limited to an unprivileged service account on that node."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"LOW","baseScore":6.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-93","description":"CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-30T20:12:07.108Z","orgId":"9119a7d8-5eab-497f-8521-727c672e3725","shortName":"cisa-cg"},"references":[{"name":"url","url":"https://github.com/kiteworks/security-advisories/security/advisories/GHSA-rpxx-jm93-w5j7"},{"name":"url","tags":["third-party-advisory"],"url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"}],"title":"Kiteworks Core Command Execution through Configuration Injection","x_generator":{"engine":"VINCE-NT 1.15.0+build.145"}}},"cveMetadata":{"assignerOrgId":"9119a7d8-5eab-497f-8521-727c672e3725","assignerShortName":"cisa-cg","cveId":"CVE-2026-102136","datePublished":"2026-09-30T20:12:07.108Z","dateReserved":"2026-09-28T17:39:13.563Z","dateUpdated":"2026-10-01T13:37:06.915Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-30 21:17:02","lastModifiedDate":"2026-10-01 14:17:18","problem_types":["CWE-93","CWE-93 CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')"],"metrics":{"cvssMetricV31":[{"source":"9119a7d8-5eab-497f-8521-727c672e3725","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2,"impactScore":3.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-10-01T13:24:21.585395Z","id":"CVE-2026-102136","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"102136","Ordinal":"1","Title":"Kiteworks Core Command Execution through Configuration Injection","CVE":"CVE-2026-102136","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"102136","Ordinal":"1","NoteData":"In multi-node deployments, an attacker who had already obtained code execution on one appliance node could submit a value through an internal cluster interface that was written into monitoring configuration on another node without sufficient validation, potentially allowing OS commands to be executed there. Execution was limited to an unprivileged service account on that node.","Type":"Description","Title":"Kiteworks Core Command Execution through Configuration Injection"}]}}}