OFFLINE
Awaiting data
Security intelligence
MinorCritical vulnerability

CVE-2026-102112 (CVSS 7.8)

NVD · officialPublished Sep 30, 2026Risk 23/100

A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root and run arbitrary commands with the highest privileges. Exploitation requires existing local access to that service account.

CVSS
7.8
AV:LocalAC:LowPR:LowUI:NoneC:HighI:HighA:High

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source