Kiteworks is a private data network (PDN). Prior to version 9.2.0, avulnerability in Kiteworks command execution functionality allows authenticated users to redirect command output to arbitrary file locations. This could be exploited to overwrite critical system files and gain elevated access. Version 9.2.0 contains a patch.
Metrics
Affected Vendors & Products
References
History
Fri, 27 Feb 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kiteworks
Kiteworks security-advisories |
|
| Vendors & Products |
Kiteworks
Kiteworks security-advisories |
Thu, 26 Feb 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kiteworks is a private data network (PDN). Prior to version 9.2.0, avulnerability in Kiteworks command execution functionality allows authenticated users to redirect command output to arbitrary file locations. This could be exploited to overwrite critical system files and gain elevated access. Version 9.2.0 contains a patch. | |
| Title | Kiteworks Core has an OS Command Injection | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-02-26T22:52:26.688Z
Updated: 2026-02-26T22:52:26.688Z
Reserved: 2026-02-26T01:52:58.733Z
Link: CVE-2026-28269
No data.
Status : Received
Published: 2026-02-26T23:16:36.910
Modified: 2026-02-26T23:16:36.910
Link: CVE-2026-28269
No data.