Description
Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did not recognize every form in which they could be supplied. An authenticated administrator could potentially use an unrecognized form to have a file of their choosing written to the gateway and executed, resulting in code execution as the gateway service account.
Published: 2026-09-30
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Kiteworks Email Protection Gateway has a flaw in case‑sensitive validation that allows authenticated administrators to submit configuration data in an unrecognized form, resulting in arbitrary files being written to the gateway and executed. This flaw permits execution of code with the privileges of the gateway service account, effectively granting an attacker full control over the service and potentially the underlying host. The vulnerability is a form of input validation failure (CWE‑178) that leads to code execution (CWE‑94).

Affected Systems

The affected product is Kiteworks Email Protection Gateway. No specific version information is provided in the advisory, so all current installations of the product are potentially vulnerable until a vendor‑supplied fix is applied. Only administrators with authentication to the gateway can exploit the flaw.

Risk and Exploitability

The CVSS score of 7.2 indicates a high impact risk. Because the EPSS score is not available, the exploitation probability cannot be quantified, but the lack of a KEV listing suggests the vulnerability is not widely exploited yet. The attack requires valid administrator credentials and the ability to send configuration payloads to the gateway. Once exploited, the attacker can write and execute any file, leading to complete compromise of the gateway service account.」

Generated by OpenCVE AI on September 30, 2026 at 22:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or upgrade to a version that includes the validation fix.
  • Restrict administrator access to the configuration interface, ensuring only trusted users have permission to modify settings.
  • Enable logging of configuration changes and monitor for unexpected file creation or execution events to detect potential abuse.

Generated by OpenCVE AI on September 30, 2026 at 22:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Kiteworks
Kiteworks kiteworks Email Protection Gateway
Vendors & Products Kiteworks
Kiteworks kiteworks Email Protection Gateway

Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did not recognize every form in which they could be supplied. An authenticated administrator could potentially use an unrecognized form to have a file of their choosing written to the gateway and executed, resulting in code execution as the gateway service account.
Title Kiteworks Email Protection Gateway Improper Handling of Case Sensitivity
Weaknesses CWE-178
CWE-94
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Kiteworks Kiteworks Email Protection Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-10-01T13:37:05.899Z

Reserved: 2026-09-28T17:39:13.563Z

Link: CVE-2026-102131

cve-icon Vulnrichment

Updated: 2026-10-01T13:32:07.663Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T21:17:01.667

Modified: 2026-10-01T14:17:17.510

Link: CVE-2026-102131

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:30:08Z

Weaknesses
  • CWE-178

    Improper Handling of Case Sensitivity

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')