OFFLINE
Awaiting data
Security intelligence
MinorCritical vulnerability

CVE-2026-102130 (CVSS 7.2)

NVD · officialPublished Sep 30, 2026Risk 23/100

Kiteworks Email Protection Gateway did not sufficiently validate the content of an uploaded backup, and allowed an administrator to influence how the application loaded it. An authenticated administrator could potentially use this to execute arbitrary code on the gateway as the underlying service account.

CVSS
7.2
AV:NetworkAC:LowPR:HighUI:NoneC:HighI:HighA:High

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source