OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102116

HIGH · CVSS 7.2 EPSS 0.64% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

An authenticated administrator of the Kiteworks Email Protection Gateway is vulnerable to a flaw that permits writing files outside designated directories, which could lead to remote code execution with the privileges of the underlying service account. Organizations using this product should prioritize patching this vulnerability to mitigate the risk of unauthorized access and potential exploitation. Immediate action is recommended for those managing sensitive data or critical infrastructure.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102116
Severity
HIGH
CVSS
7.2
EPSS
0.64%

Original NVD Description

-A weakness could have allowed an authenticated Kiteworks Email Protection Gateway administrator to write a file outside its intended location and cause the application to execute it, potentially resulting in remote code execution as the underlying service account.