CVE-2026-102143
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Summary
An unauthenticated attacker could cause a file with attacker-controlled content to be written to the appliance filesystem through an administrative upload handler that did not properly authenticate the request. This did not by itself result in code execution, which would require a separate vulnerability to place the file in an executable location.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Kiteworks | Email Protection Gateway | 0 < 9.5.1 | affected |
| Kiteworks | Email Protection Gateway | 9.5.1 | unaffected |
Weaknesses
- CWE-306: CWE-306 Missing Authentication for Critical Function
- CWE-434: CWE-434 Unrestricted Upload of File with Dangerous Type
References
- https://github.com/kiteworks/security-advisories/security/advisories/GHSA-3p9g-jh62-8f89
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.