Kiteworks Email Protection Gateway remote code execution
Summary
| CVE | CVE-2026-102097 |
|---|---|
| State | PUBLISHED |
| Assigner | cisa-cg |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-30 21:16:56 UTC |
| Updated | 2026-10-01 14:17:13 UTC |
| Description | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Remote Code Execution. Kiteworks Email Protection Gateway allowed an authenticated administrator to import configuration whose contents were not sufficiently validated before being processed. A crafted submission could potentially allow arbitrary commands to be executed on the affected gateway. |
Risk And Classification
Primary CVSS: v3.1 7.2 HIGH from 9119a7d8-5eab-497f-8521-727c672e3725
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.007070000 probability, percentile 0.517740000 (date 2026-10-02)
Problem Types: CWE-22 | CWE-94 | CWE-22 CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | CWE-94 CWE-94 Improper Control of Generation of Code ('Code Injection')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 9119a7d8-5eab-497f-8521-727c672e3725 | Secondary | 7.2 | HIGH | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 7.2 | HIGH | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
HighUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Kiteworks | Email Protection Gateway | affected 9.5.0 custom | Not specified |
| CNA | Kiteworks | Email Protection Gateway | unaffected 9.5.0 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json | 9119a7d8-5eab-497f-8521-727c672e3725 | raw.githubusercontent.com | |
| github.com/kiteworks/security-advisories/security/advisories/GHSA-465g-w... | 9119a7d8-5eab-497f-8521-727c672e3725 | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: wlayzz, https://yeswehack.com/hunters/wlayzz (en)
CNA: Icare, https://yeswehack.com/hunters/icare (en)
CNA: truff, https://yeswehack.com/hunters/truff (en)
There are currently no legacy QID mappings associated with this CVE.