CVE-2026-102131: Kiteworks Email Protection Gateway Improper Handling of Case Sensitivity
Published Sep 30, 2026
·Updated
Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did not recognize every form in which they could be supplied. An authenticated administrator could potentially use an unrecognized form to have a file of their choosing written to the gateway and executed, resulting in code execution as the gateway service account.
Affected Software
1 affected component
Kiteworks Email Protection Gateway
Event History
Sep 30, 2026
CVE Published
via MITRE·08:13 PM
Data Sourced
via MITRE·08:13 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness