OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102130

HIGH · CVSS 7.2 EPSS 0.39% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The Kiteworks Email Protection Gateway is vulnerable due to insufficient validation of uploaded backup content, allowing an authenticated administrator to manipulate the application’s loading process. This flaw could enable the execution of arbitrary code with the privileges of the underlying service account, posing a significant security risk. Organizations using this gateway should prioritize remediation to prevent potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102130
Severity
HIGH
CVSS
7.2
EPSS
0.39%

Original NVD Description

Kiteworks Email Protection Gateway did not sufficiently validate the content of an uploaded backup, and allowed an administrator to influence how the application loaded it. An authenticated administrator could potentially use this to execute arbitrary code on the gateway as the underlying service account.