Kiteworks is a private data network (PDN). Prior to version 9.2.0, avulnerability in Kiteworks command execution functionality allows authenticated users to redirect command output to arbitrary file locations. This could be exploited to overwrite critical system files and gain elevated access. Version 9.2.0 contains a patch.
Metrics
Affected Vendors & Products
References
History
Tue, 03 Mar 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Accellion
Accellion kiteworks |
|
| CPEs | cpe:2.3:a:accellion:kiteworks:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Accellion
Accellion kiteworks |
Fri, 27 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 27 Feb 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kiteworks
Kiteworks security-advisories |
|
| Vendors & Products |
Kiteworks
Kiteworks security-advisories |
Thu, 26 Feb 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kiteworks is a private data network (PDN). Prior to version 9.2.0, avulnerability in Kiteworks command execution functionality allows authenticated users to redirect command output to arbitrary file locations. This could be exploited to overwrite critical system files and gain elevated access. Version 9.2.0 contains a patch. | |
| Title | Kiteworks Core has an OS Command Injection | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-02-26T22:52:26.688Z
Updated: 2026-02-27T17:53:05.993Z
Reserved: 2026-02-26T01:52:58.733Z
Link: CVE-2026-28269
Updated: 2026-02-27T17:53:00.112Z
Status : Analyzed
Published: 2026-02-26T23:16:36.910
Modified: 2026-03-03T19:53:18.500
Link: CVE-2026-28269
No data.