CVE-2026-102117: Kiteworks Core
High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.
On deployments where the remote-support capability is licensed and enabled, an authenticated System Administrator who also possessed the key protecting the submitted data could redirect the underlying system's outbound support connection to a destination of their choosing. That destination could then have operating-system commands executed on the node and receive their output, potentially resulting in remote code execution with the privileges of a local service account.
Affected products
- Kiteworks Core: before 9.5.1 (fixed in 9.5.1)
Published 2026-09-30. Last modified 2026-10-01.