CVE-2026-102116: Kiteworks Email Protection Gateway Path Traversal
Published Sep 30, 2026
·Updated
-A weakness could have allowed an authenticated Kiteworks Email Protection Gateway administrator to write a file outside its intended location and cause the application to execute it, potentially resulting in remote code execution as the underlying service account.
Affected Software
1 affected component
Kiteworks Email Protection Gateway
Event History
Sep 30, 2026
CVE Published
via MITRE·08:19 PM
Data Sourced
via MITRE·08:19 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Is unauthenticated exploitation indicated?
No. Exploitation requires an authenticated administrator account for Kiteworks Email Protection Gateway.
2
What account context could code execution obtain?
The application could execute an attacker-written file as the underlying service account.