Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-102096

Kiteworks Core before version 9.5.0 is vulnerable to OS Command Injection that allows an authenticated administrator to upload a configuration package whose contents were not sufficiently validated before being processed. A crafted package could cause the underlying system to execute arbitrary operating-system commands, potentially with elevated privileges, on the affected appliance.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.011
EPSS Ranking 64.3%
CVSS Severity
CVSS v3 Score 7.2
Products affected by CVE-2026-102096


Contact Us

Shodan ® - All rights reserved