PT-2026-103569 · Kiteworks · Core
CVSS v3.1
6.3
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
The product name cannot be determined (affected versions not specified)
Description
In multi-node deployments, an attacker with existing code execution on one appliance node can submit a value via an internal cluster interface. This value is written into the monitoring configuration of another node without sufficient validation, which may allow the execution of OS commands. The execution is restricted to an unprivileged service account on the target node.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Core