CVE-2026-102119: Kiteworks Email Protection Gateway Path Traversal
A path traversal weakness in an optional, non-default administrative feature allowed an authenticated administrator to move files to unintended locations outside the feature's designated directory. This could potentially be leveraged to execute arbitrary code on the underlying system.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Only deployments where the optional administrative feature is enabled are exposed. The feature is non-default, and exploitation requires an authenticated administrator.
What level of access does an attacker need?
An attacker must already have administrator authentication to use the vulnerable feature. The attack can be performed remotely and does not require user interaction.
What could exploitation allow?
An authenticated administrator could move files outside the feature's intended directory. This may be leveraged to execute arbitrary code on the underlying system, affecting confidentiality, integrity, and availability.