{"api_version":"1","generated_at":"2026-10-01T15:03:19+00:00","cve":"CVE-2026-102143","urls":{"html":"https://cve.report/CVE-2026-102143","api":"https://cve.report/api/cve/CVE-2026-102143.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-102143","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-102143"},"summary":{"title":"Kiteworks Email Protection Gateway Unrestricted Upload of File with Dangerous Type","description":"An unauthenticated attacker could cause a file with attacker-controlled content to be written to the appliance filesystem through an administrative upload handler that did not properly authenticate the request. This did not by itself result in code execution, which would require a separate vulnerability to place the file in an executable location.","state":"PUBLISHED","assigner":"cisa-cg","published_at":"2026-09-30 21:17:03","updated_at":"2026-10-01 02:17:43"},"problem_types":["CWE-306","CWE-434","CWE-306 CWE-306 Missing Authentication for Critical Function","CWE-434 CWE-434 Unrestricted Upload of File with Dangerous Type"],"metrics":[{"version":"3.1","source":"9119a7d8-5eab-497f-8521-727c672e3725","type":"Secondary","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"}}],"references":[{"url":"https://github.com/kiteworks/security-advisories/security/advisories/GHSA-3p9g-jh62-8f89","name":"https://github.com/kiteworks/security-advisories/security/advisories/GHSA-3p9g-jh62-8f89","refsource":"9119a7d8-5eab-497f-8521-727c672e3725","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json","name":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json","refsource":"9119a7d8-5eab-497f-8521-727c672e3725","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-102143","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102143","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Kiteworks","product":"Email Protection Gateway","version":"affected 9.5.1 custom","platforms":[]},{"source":"CNA","vendor":"Kiteworks","product":"Email Protection Gateway","version":"unaffected 9.5.1","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Supr4s, https://yeswehack.com/hunters/supr4s","lang":"en"},{"source":"CNA","value":"wlayzz, https://yeswehack.com/hunters/wlayzz","lang":"en"},{"source":"CNA","value":"Icare, https://yeswehack.com/hunters/icare","lang":"en"},{"source":"CNA","value":"truff, https://yeswehack.com/hunters/truff","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unknown","product":"Email Protection Gateway","vendor":"Kiteworks","versions":[{"lessThan":"9.5.1","status":"affected","version":"0","versionType":"custom"},{"status":"unaffected","version":"9.5.1"}]}],"credits":[{"lang":"en","value":"Supr4s, https://yeswehack.com/hunters/supr4s"},{"lang":"en","value":"wlayzz, https://yeswehack.com/hunters/wlayzz"},{"lang":"en","value":"Icare, https://yeswehack.com/hunters/icare"},{"lang":"en","value":"truff, https://yeswehack.com/hunters/truff"}],"datePublic":"2026-09-30T00:00:00.000Z","descriptions":[{"lang":"en","value":"An unauthenticated attacker could cause a file with attacker-controlled content to be written to the appliance filesystem through an administrative upload handler that did not properly authenticate the request. This did not by itself result in code execution, which would require a separate vulnerability to place the file in an executable location."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-306","description":"CWE-306 Missing Authentication for Critical Function","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-434","description":"CWE-434 Unrestricted Upload of File with Dangerous Type","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-30T20:10:09.419Z","orgId":"9119a7d8-5eab-497f-8521-727c672e3725","shortName":"cisa-cg"},"references":[{"name":"url","url":"https://github.com/kiteworks/security-advisories/security/advisories/GHSA-3p9g-jh62-8f89"},{"name":"url","tags":["third-party-advisory"],"url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"}],"title":"Kiteworks Email Protection Gateway Unrestricted Upload of File with Dangerous Type","x_generator":{"engine":"VINCE-NT 1.15.0+build.145"}}},"cveMetadata":{"assignerOrgId":"9119a7d8-5eab-497f-8521-727c672e3725","assignerShortName":"cisa-cg","cveId":"CVE-2026-102143","datePublished":"2026-09-30T20:10:09.419Z","dateReserved":"2026-09-28T17:39:13.564Z","dateUpdated":"2026-09-30T20:10:09.419Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-30 21:17:03","lastModifiedDate":"2026-10-01 02:17:43","problem_types":["CWE-306","CWE-434","CWE-306 CWE-306 Missing Authentication for Critical Function","CWE-434 CWE-434 Unrestricted Upload of File with Dangerous Type"],"metrics":{"cvssMetricV31":[{"source":"9119a7d8-5eab-497f-8521-727c672e3725","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"102143","Ordinal":"1","Title":"Kiteworks Email Protection Gateway Unrestricted Upload of File w","CVE":"CVE-2026-102143","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"102143","Ordinal":"1","NoteData":"An unauthenticated attacker could cause a file with attacker-controlled content to be written to the appliance filesystem through an administrative upload handler that did not properly authenticate the request. This did not by itself result in code execution, which would require a separate vulnerability to place the file in an executable location.","Type":"Description","Title":"Kiteworks Email Protection Gateway Unrestricted Upload of File w"}]}}}