Description
Kiteworks Email Protection Gateway did not sufficiently validate the content of an uploaded backup, and allowed an administrator to influence how the application loaded it. An authenticated administrator could potentially use this to execute arbitrary code on the gateway as the underlying service account.
Published: 2026-09-30
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Kiteworks Email Protection Gateway allowed an authenticated administrator to upload a backup file that the application loaded without adequate validation. The flaw combines uncontrolled file type upload (CWE‑434) and code injection (CWE‑94), enabling the attacker to execute arbitrary code on the gateway under the rights of the underlying service account and thereby compromising the protected environment.

Affected Systems

The vulnerable component is Kiteworks Email Protection Gateway. No specific product versions were disclosed in the advisory, so all installations remain potentially impacted until an update is applied.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity. Because the exploit requires that the attacker already possesses an authenticated administrator account, the threat is primarily an insider or a compromised account scenario. The EPSS score is not available, and the vulnerability is not currently listed in CISA KEV, but the remote code execution capability means that once an administrator‑level credential is compromised, the attacker can fully control the gateway service.

Generated by OpenCVE AI on September 30, 2026 at 22:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest vendor patch for Kiteworks Email Protection Gateway that includes proper backup file validation.
  • Restrict or disable the ability of administrators to upload or restore backup files unless absolutely required, and enforce strict type checking on any uploaded content.
  • Revoke and reset credentials for all administrator accounts and ensure that least‑privilege access control is enforced for future admin accounts.

Generated by OpenCVE AI on September 30, 2026 at 22:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Kiteworks
Kiteworks kiteworks Email Protection Gateway
Vendors & Products Kiteworks
Kiteworks kiteworks Email Protection Gateway

Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description Kiteworks Email Protection Gateway did not sufficiently validate the content of an uploaded backup, and allowed an administrator to influence how the application loaded it. An authenticated administrator could potentially use this to execute arbitrary code on the gateway as the underlying service account.
Title Kiteworks Email Protection Gateway Remote Code Execution
Weaknesses CWE-434
CWE-94
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Kiteworks Kiteworks Email Protection Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-10-01T13:37:05.756Z

Reserved: 2026-09-28T17:39:13.563Z

Link: CVE-2026-102130

cve-icon Vulnrichment

Updated: 2026-10-01T13:32:06.272Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T21:17:01.533

Modified: 2026-10-01T14:17:17.390

Link: CVE-2026-102130

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:30:08Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')