PT-2026-103535 · Kiteworks · Kiteworks Email Protection Gateway
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kiteworks Email Protection Gateway versions prior to 9.5.0
Description
An authenticated administrator can achieve Remote Code Execution by importing a configuration with contents that are not sufficiently validated before processing. A crafted submission allows the execution of arbitrary commands on the gateway.
Recommendations
Update Kiteworks Email Protection Gateway to version 9.5.0 or later.
Fix
RCE
Code Injection
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kiteworks Email Protection Gateway