{"api_version":"1","generated_at":"2026-10-04T02:48:35+00:00","cve":"CVE-2026-102089","urls":{"html":"https://cve.report/CVE-2026-102089","api":"https://cve.report/api/cve/CVE-2026-102089.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-102089","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-102089"},"summary":{"title":"Kiteworks Email Protection Gateway path traversal","description":"Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to a path traversal weakness in an administrative import function allowed an authenticated administrator to write files to arbitrary locations on the server. This could potentially be leveraged to execute arbitrary code on the underlying system.","state":"PUBLISHED","assigner":"cisa-cg","published_at":"2026-09-30 21:16:55","updated_at":"2026-10-01 14:17:12"},"problem_types":["CWE-22","CWE-22 CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"metrics":[{"version":"3.1","source":"9119a7d8-5eab-497f-8521-727c672e3725","type":"Secondary","score":"7.2","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.2","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.2,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json","name":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json","refsource":"9119a7d8-5eab-497f-8521-727c672e3725","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/kiteworks/security-advisories/security/advisories/GHSA-p853-p65q-2vc8","name":"https://github.com/kiteworks/security-advisories/security/advisories/GHSA-p853-p65q-2vc8","refsource":"9119a7d8-5eab-497f-8521-727c672e3725","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-102089","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102089","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Kiteworks","product":"Email Protection Gateway","version":"affected 9.5.0 custom","platforms":[]},{"source":"CNA","vendor":"Kiteworks","product":"Email Protection Gateway","version":"unaffected 9.5.0","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Supr4s, https://yeswehack.com/hunters/Supr4s","lang":"en"},{"source":"CNA","value":"wlayzz, https://yeswehack.com/hunters/wlayzz","lang":"en"},{"source":"CNA","value":"Icare, https://yeswehack.com/hunters/Icare","lang":"en"},{"source":"CNA","value":"truff, https://yeswehack.com/hunters/truff","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"102089","cve":"CVE-2026-102089","epss":"0.005040000","percentile":"0.409410000","score_date":"2026-10-03","updated_at":"2026-10-04 00:03:18"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-102089","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-10-01T13:29:22.647132Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-10-01T13:37:09.618Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unknown","product":"Email Protection Gateway","vendor":"Kiteworks","versions":[{"lessThan":"9.5.0","status":"affected","version":"0","versionType":"custom"},{"status":"unaffected","version":"9.5.0"}]}],"credits":[{"lang":"en","value":"Supr4s, https://yeswehack.com/hunters/Supr4s"},{"lang":"en","value":"wlayzz, https://yeswehack.com/hunters/wlayzz"},{"lang":"en","value":"Icare, https://yeswehack.com/hunters/Icare"},{"lang":"en","value":"truff, https://yeswehack.com/hunters/truff"}],"datePublic":"2026-09-30T00:00:00.000Z","descriptions":[{"lang":"en","value":"Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to a path traversal weakness in an administrative import function allowed an authenticated administrator to write files to arbitrary locations on the server. This could potentially be leveraged to execute arbitrary code on the underlying system."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.2,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-22","description":"CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-30T20:05:02.985Z","orgId":"9119a7d8-5eab-497f-8521-727c672e3725","shortName":"cisa-cg"},"references":[{"name":"url","tags":["vendor-advisory"],"url":"https://github.com/kiteworks/security-advisories/security/advisories/GHSA-p853-p65q-2vc8"},{"name":"url","tags":["third-party-advisory"],"url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"}],"title":"Kiteworks Email Protection Gateway path traversal","x_generator":{"engine":"VINCE-NT 1.15.0+build.145"}}},"cveMetadata":{"assignerOrgId":"9119a7d8-5eab-497f-8521-727c672e3725","assignerShortName":"cisa-cg","cveId":"CVE-2026-102089","datePublished":"2026-09-30T20:05:02.985Z","dateReserved":"2026-09-28T17:39:13.560Z","dateUpdated":"2026-10-01T13:37:09.618Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-30 21:16:55","lastModifiedDate":"2026-10-01 14:17:12","problem_types":["CWE-22","CWE-22 CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"metrics":{"cvssMetricV31":[{"source":"9119a7d8-5eab-497f-8521-727c672e3725","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-10-01T13:29:22.647132Z","id":"CVE-2026-102089","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"102089","Ordinal":"1","Title":"Kiteworks Email Protection Gateway path traversal","CVE":"CVE-2026-102089","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"102089","Ordinal":"1","NoteData":"Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to a path traversal weakness in an administrative import function allowed an authenticated administrator to write files to arbitrary locations on the server. This could potentially be leveraged to execute arbitrary code on the underlying system.","Type":"Description","Title":"Kiteworks Email Protection Gateway path traversal"}]}}}