CVE-2026-102096
EUVD-2026-9037930.09.2026, 21:16
Kiteworks Core before version 9.5.0 is vulnerable to OS Command Injection that allows an authenticated administrator to upload a configuration package whose contents were not sufficiently validated before being processed. A crafted package could cause the underlying system to execute arbitrary operating-system commands, potentially with elevated privileges, on the affected appliance.
Awaiting analysis
This vulnerability is currently awaiting analysis.