VDB

CVE-2026-102131

CVE-2026-102131 PUBLISHED CVSS 7.2 HIGH

Reported by cisa-cg · Published September 30, 2026

Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did not recognize every form in which they could be supplied. An authenticated administrator could potentially use an unrecognized form to have a file of their choosing written to the gateway and executed, resulting in code execution as the gateway service account.

Risk Scores

CVSS 3.1
7.2
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
KiteworksEmail Protection Gateway0, 9.5.0
KiteworksEmail Protection Gateway0, 9.5.0, 0

Timeline

  • Sep 30, 2026 Coalition ESS Score
  • Sep 30, 2026 CVE Published
  • Oct 1, 2026 EPSS Score
  • Oct 2, 2026 EPSS Score
  • Oct 6, 2026 EPSS Score
  • Oct 8, 2026 CVE Updated

References

  • url vendor-advisory
  • url third-party-advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›