CVE-2026-102116

Summary

-A weakness could have allowed an authenticated Kiteworks Email Protection Gateway administrator to write a file outside its intended location and cause the application to execute it, potentially resulting in remote code execution as the underlying service account.

Affected Software

VendorProductVersion RangeStatus
KiteworksEmail Protection Gateway0 < 9.5.0affected
KiteworksEmail Protection Gateway9.5.0unaffected

Weaknesses

  • CWE-22: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
  • CWE-91: CWE-91 XML Injection (aka Blind XPath Injection)

References