CVE-2026-102096 UNKNOWN

CVE-2026-102096

Published: 2026-09-30

Description

Kiteworks Core before version 9.5.0 is vulnerable to OS Command Injection that allows an authenticated administrator to upload a configuration package whose contents were not sufficiently validated before being processed. A crafted package could cause the underlying system to execute arbitrary operating-system commands, potentially with elevated privileges, on the affected appliance.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…