cbcvebase.
CVE-2026-102133
published 2026-09-30

CVE-2026-102133: An optional, separately licensed repository-connector feature in Kiteworks Core did not neutralize special characters in a user-supplied path before passing it…

PriorityP343medium6.6CVSS 3.1
AVNACHPRHUINSUCHIHAH
EPSS
0.40%
32.1th percentile
An optional, separately licensed repository-connector feature in Kiteworks Core did not neutralize special characters in a user-supplied path before passing it to an external command. An authenticated system administrator could inject additional commands and write arbitrary content to files owned by the service account running the connector, enabling code execution in that account's context; exploitation additionally requires network egress from the appliance to a system under the attacker's control.

Affected

1 ranges
VendorProductVersion rangeFixed in
kiteworkscore< 9.5.19.5.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.