CVE-2026-102113: Accellion Kiteworks
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root. A privileged routine did not safely handle a filesystem path that the lower-privileged account could influence, allowing the attacker to cause a root-owned operation to run arbitrary commands with the highest privileges. Exploitation requires existing local access to that service account.
Affected products
- Accellion Kiteworks: before 9.5.0 (fixed in 9.5.0)
Published 2026-09-30. Last modified 2026-10-07.