CVE-2026-102143

Summary

An unauthenticated attacker could cause a file with attacker-controlled content to be written to the appliance filesystem through an administrative upload handler that did not properly authenticate the request. This did not by itself result in code execution, which would require a separate vulnerability to place the file in an executable location.

Affected Software

VendorProductVersion RangeStatus
KiteworksEmail Protection Gateway0 < 9.5.1affected
KiteworksEmail Protection Gateway9.5.1unaffected

Weaknesses

  • CWE-306: CWE-306 Missing Authentication for Critical Function
  • CWE-434: CWE-434 Unrestricted Upload of File with Dangerous Type

References