CVE-2026-102096: Accellion Kiteworks
High severity, CVSS 7.2. EPSS: 3.3% chance of exploitation in the next 30 days.
Kiteworks Core before version 9.5.0 is vulnerable to OS Command Injection that allows an authenticated administrator to upload a configuration package whose contents were not sufficiently validated before being processed. A crafted package could cause the underlying system to execute arbitrary operating-system commands, potentially with elevated privileges, on the affected appliance.
Affected products
- Accellion Kiteworks: before 9.5.0 (fixed in 9.5.0)
Published 2026-09-30. Last modified 2026-10-07.