OFFLINE
Awaiting data
Security intelligence
MinorCritical vulnerability

CVE-2026-102131 (CVSS 7.2)

NVD · officialPublished Sep 30, 2026Risk 23/100

Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did not recognize every form in which they could be supplied. An authenticated administrator could potentially use an unrecognized form to have a file of their choosing written to the gateway and executed, resulting in code execution as the gateway service account.

CVSS
7.2
AV:NetworkAC:LowPR:HighUI:NoneC:HighI:HighA:High

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source