CVE-2026-102131
7.2
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Summary
Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did not recognize every form in which they could be supplied. An authenticated administrator could potentially use an unrecognized form to have a file of their choosing written to the gateway and executed, resulting in code execution as the gateway service account.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Kiteworks | Email Protection Gateway | 0 < 9.5.0 | affected |
| Kiteworks | Email Protection Gateway | 9.5.0 | unaffected |
Weaknesses
- CWE-94: CWE-94 Improper Control of Generation of Code ('Code Injection')
- CWE-178: CWE-178 Improper Handling of Case Sensitivity
References
- https://github.com/kiteworks/security-advisories/security/advisories/GHSA-62f6-c955-4fhq
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.