VDB

GCVE-110-NCSC-2026-408

GCVE-110-NCSC-2026-408
Advisory PublishedCVSS 7.2/10
Vulnetix · Advisory published October 8, 2026
Kiteworks Email Protection Gateway versions prior to 9.5.0 contain a path traversal vulnerability in an admin import function that allows authenticated administrators to write files to arbitrary server locations, potentially leading to arbitrary code execution.

Weaknesses (CWE)

CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-601URL Redirection to Untrusted Site ('Open Redirect')CWE-918Server-Side Request Forgery (SSRF)CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-470Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')CWE-502Deserialization of Untrusted DataCWE-639Authorization Bypass Through User-Controlled KeyCWE-306Missing Authentication for Critical FunctionCWE-1284Improper Validation of Specified Quantity in InputCWE-59Improper Link Resolution Before File Access ('Link Following')CWE-640Weak Password Recovery Mechanism for Forgotten PasswordCWE-807Reliance on Untrusted Inputs in a Security DecisionCWE-250Execution with Unnecessary PrivilegesCWE-863Incorrect AuthorizationCWE-653Improper Isolation or CompartmentalizationCWE-611Improper Restriction of XML External Entity ReferenceCWE-266Incorrect Privilege AssignmentCWE-434Unrestricted Upload of File with Dangerous TypeCWE-178Improper Handling of Case SensitivityCWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')CWE-420Unprotected Alternate ChannelCWE-93Improper Neutralization of CRLF Sequences ('CRLF Injection')CWE-73External Control of File Name or PathCWE-1336Improper Neutralization of Special Elements Used in a Template Engine

Risk Scores

CVSS 3.1
7.2/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
Kiteworksvers:unknown/*——

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

3,450 records in the GCVE database · Updated October 8, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›