File Upload Vulnerability in Kiteworks Appliance
CVE-2026-102143
7.5HIGH
What is CVE-2026-102143?
An unauthenticated attacker can manipulate an administrative upload handler within the Kiteworks Appliance to write malicious files to the filesystem. While this vulnerability does not directly lead to code execution, it allows for the placement of user-controlled content on the system, potentially paving the way for future exploits or further attacks. Proper authentication mechanisms are essential to prevent unauthorized access and maintain system integrity.
Affected Version(s)
Email Protection Gateway 0 < 9.5.1
Email Protection Gateway 9.5.1
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Supr4s, https://yeswehack.com/hunters/supr4s
wlayzz, https://yeswehack.com/hunters/wlayzz
Icare, https://yeswehack.com/hunters/icare
truff, https://yeswehack.com/hunters/truff
