CVE-2026-102146: CWE-73 External Control of File Name or Path in Kiteworks Email Protection Gateway
CVE-2026-102146 is a vulnerability in Kiteworks Email Protection Gateway where an authenticated administrator with limited delegated permissions can write files with attacker-controlled content to arbitrary locations accessible by the service account. This allows privilege escalation beyond intended limits, potentially altering application files or configurations and disrupting service availability.
AI Analysis
Technical Summary
This vulnerability involves external control of file name or path (CWE-73) in the Kiteworks Email Protection Gateway. An authenticated administrator with limited delegated permissions can write files to arbitrary locations accessible by the Email Protection Gateway service account. This unauthorized file write capability can be leveraged to modify application files or configurations or cause denial of service by disrupting service availability. The CVSS 3.1 score is 6.5 (medium severity), reflecting network attack vector, low attack complexity, high privileges required, no user interaction, unchanged scope, no confidentiality impact, but high integrity and availability impacts. The affected versions are all versions prior to 9.5.1.
Potential Impact
An attacker with authenticated limited delegated administrator permissions can exceed their intended privileges by writing files with attacker-controlled content to arbitrary locations accessible by the service account. This can lead to unauthorized modification of application files or configuration, potentially disrupting the availability of the Email Protection Gateway service. There is no confidentiality impact reported.
Mitigation Recommendations
No patch or official fix information is provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict administrator permissions carefully and monitor for unauthorized file modifications.
CVE-2026-102146: CWE-73 External Control of File Name or Path in Kiteworks Email Protection Gateway
Description
CVE-2026-102146 is a vulnerability in Kiteworks Email Protection Gateway where an authenticated administrator with limited delegated permissions can write files with attacker-controlled content to arbitrary locations accessible by the service account. This allows privilege escalation beyond intended limits, potentially altering application files or configurations and disrupting service availability.
CVSS v3.1
Score 6.5medium
Affected software
Kiteworks
Email Protection Gateway
pkg:github/kiteworks/email-protection-gatewayRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves external control of file name or path (CWE-73) in the Kiteworks Email Protection Gateway. An authenticated administrator with limited delegated permissions can write files to arbitrary locations accessible by the Email Protection Gateway service account. This unauthorized file write capability can be leveraged to modify application files or configurations or cause denial of service by disrupting service availability. The CVSS 3.1 score is 6.5 (medium severity), reflecting network attack vector, low attack complexity, high privileges required, no user interaction, unchanged scope, no confidentiality impact, but high integrity and availability impacts. The affected versions are all versions prior to 9.5.1.
Potential Impact
An attacker with authenticated limited delegated administrator permissions can exceed their intended privileges by writing files with attacker-controlled content to arbitrary locations accessible by the service account. This can lead to unauthorized modification of application files or configuration, potentially disrupting the availability of the Email Protection Gateway service. There is no confidentiality impact reported.
Mitigation Recommendations
No patch or official fix information is provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict administrator permissions carefully and monitor for unauthorized file modifications.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- cisa-cg
- Date Reserved
- 2026-09-28T17:39:13.564Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abd72532a4e24523d8ec0dd
Added to database: 09/30/2026, 20:34:27 UTC
Last enriched: 09/30/2026, 20:48:47 UTC
Last updated: 10/01/2026, 03:59:37 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.