Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kiteworks
Kiteworks kiteworks Email Protection Gateway |
|
| Vendors & Products |
Kiteworks
Kiteworks kiteworks Email Protection Gateway |
Thu, 01 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 30 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did not recognize every form in which they could be supplied. An authenticated administrator could potentially use an unrecognized form to have a file of their choosing written to the gateway and executed, resulting in code execution as the gateway service account. | |
| Title | Kiteworks Email Protection Gateway Improper Handling of Case Sensitivity | |
| Weaknesses | CWE-178 CWE-94 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2026-10-01T13:37:05.899Z
Reserved: 2026-09-28T17:39:13.563Z
Link: CVE-2026-102131
Updated: 2026-10-01T13:32:07.663Z
Status : Awaiting Analysis
Published: 2026-09-30T21:17:01.667
Modified: 2026-10-01T14:17:17.510
Link: CVE-2026-102131
No data.
OpenCVE Enrichment
Updated: 2026-10-01T15:30:08Z