Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did not recognize every form in which they could be supplied. An authenticated administrator could potentially use an unrecognized form to have a file of their choosing written to the gateway and executed, resulting in code execution as the gateway service account.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 30 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did not recognize every form in which they could be supplied. An authenticated administrator could potentially use an unrecognized form to have a file of their choosing written to the gateway and executed, resulting in code execution as the gateway service account. | |
| Title | Kiteworks Email Protection Gateway Improper Handling of Case Sensitivity | |
| Weaknesses | CWE-178 CWE-94 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2026-09-30T20:13:43.236Z
Reserved: 2026-09-28T17:39:13.563Z
Link: CVE-2026-102131
No data.
Status : Received
Published: 2026-09-30T21:17:01.667
Modified: 2026-09-30T21:17:01.667
Link: CVE-2026-102131
No data.
OpenCVE Enrichment
Updated: 2026-09-30T22:15:14Z