CVE-2026-102096

Kiteworks Core before version 9.5.0 is vulnerable to OS Command Injection that allows an authenticated administrator to upload a configuration package whose contents were not sufficiently validated before being processed. A crafted package could cause the underlying system to execute arbitrary operating-system commands, potentially with elevated privileges, on the affected appliance.

  • Published Sep 30, 2026
  • CVSS 7.2 high
  • 1.1% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-102096 at the National Vulnerability Database