Vulnerability Details CVE-2026-102141
Two Kiteworks Core cluster-management operations did not validate file paths supplied to them, so an attacker holding root on one node of a cluster could write files as root onto another node and cause them to be executed there. Exploitation requires backend root access on a cluster node and a pending software patch present on the target node.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 0.8%
CVSS Severity
CVSS v3 Score 6.7
Products affected by CVE-2026-102141
-
cpe:2.3:a:accellion:kiteworks:7.3.0
-
cpe:2.3:a:accellion:kiteworks:7.3.1
-
cpe:2.3:a:accellion:kiteworks:7.3.2
-
cpe:2.3:a:accellion:kiteworks:7.4.0
-
cpe:2.3:a:accellion:kiteworks:9.1.0
-
cpe:2.3:a:accellion:kiteworks:9.2.0
-
cpe:2.3:a:accellion:kiteworks:9.2.1
-
cpe:2.3:a:accellion:kiteworks:9.3.0