OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102131

HIGH · CVSS 7.2 EPSS 0.39% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The Kiteworks Email Protection Gateway is vulnerable due to improper validation of configuration settings, allowing authenticated administrators to exploit this flaw by supplying unrecognized input forms. This could lead to arbitrary file writing and execution, compromising the gateway service account. Organizations utilizing this gateway should prioritize remediation to prevent potential code execution and unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102131
Severity
HIGH
CVSS
7.2
EPSS
0.39%

Original NVD Description

Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did not recognize every form in which they could be supplied. An authenticated administrator could potentially use an unrecognized form to have a file of their choosing written to the gateway and executed, resulting in code execution as the gateway service account.