Impact
Kiteworks Email Protection Gateway allowed an authenticated administrator to upload a backup file that the application loaded without adequate validation. The flaw combines uncontrolled file type upload (CWE‑434) and code injection (CWE‑94), enabling the attacker to execute arbitrary code on the gateway under the rights of the underlying service account and thereby compromising the protected environment.
Affected Systems
The vulnerable component is Kiteworks Email Protection Gateway. No specific product versions were disclosed in the advisory, so all installations remain potentially impacted until an update is applied.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity. Because the exploit requires that the attacker already possesses an authenticated administrator account, the threat is primarily an insider or a compromised account scenario. The EPSS score is not available, and the vulnerability is not currently listed in CISA KEV, but the remote code execution capability means that once an administrator‑level credential is compromised, the attacker can fully control the gateway service.
OpenCVE Enrichment