CVE-2026-28269
Published: 26 February 2026
Summary
CVE-2026-28269 is a medium-severity OS Command Injection (CWE-78) vulnerability in Accellion Kiteworks. Its CVSS base score is 5.9 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 8.5th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
Threat & Defense at a Glance
Threat & Defense Details
Likely Mitigating ControlsAI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
OS command injection (CWE-78) in network-accessible Kiteworks app enables Unix shell command execution via output redirection to overwrite system files for privilege escalation.
NVD Description
Kiteworks is a private data network (PDN). Prior to version 9.2.0, avulnerability in Kiteworks command execution functionality allows authenticated users to redirect command output to arbitrary file locations. This could be exploited to overwrite critical system files and gain elevated…
more
access. Version 9.2.0 contains a patch.
Deeper analysisAI
CVE-2026-28269 affects Kiteworks, a private data network (PDN), in versions prior to 9.2.0. The vulnerability lies in the command execution functionality, where authenticated users can redirect command output to arbitrary file locations. Classified as CWE-78 (OS Command Injection), it has a CVSS v3.1 base score of 5.9 (AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N), indicating network accessibility but requiring high privileges and attack complexity.
High-privilege authenticated users can exploit this vulnerability over the network without user interaction. Successful exploitation allows overwriting critical system files, which could lead to elevated access on the affected system.
Kiteworks version 9.2.0 contains a patch addressing this issue. Additional details are available in the security advisory at https://github.com/kiteworks/security-advisories/security/advisories/GHSA-6j64-6fpp-9453.
Details
- CWE(s)