MEDIUM 6.6 NVD

CVE-2026-102133

An optional, separately licensed repository-connector feature in Kiteworks Core did not neutralize special characters in a user-supplied path before passing it

An optional, separately licensed repository-connector feature in Kiteworks Core did not neutralize special characters in a user-supplied path before passing it to an external command. An authenticated system administrator could inject additional commands and write arbitrary content to files owned by the service account running the connector, enabling code execution in that account's context; exploitation additionally requires network egress from the appliance to a system under the attacker's control.

References

Published: 2026-09-30 · Source: NVD · Feed updated: 2026-10-01
This medium severity vulnerability with a CVSS score of 6.6 was published on 2026-09-30 via NVD.
vulnfeed aggregates 9519 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.