File Upload Vulnerability in Kiteworks Appliance
CVE-2026-102143

7.5HIGH

Key Information:

Vendor

Kiteworks

Vendor
CVE Published:
30 September 2026

What is CVE-2026-102143?

An unauthenticated attacker can manipulate an administrative upload handler within the Kiteworks Appliance to write malicious files to the filesystem. While this vulnerability does not directly lead to code execution, it allows for the placement of user-controlled content on the system, potentially paving the way for future exploits or further attacks. Proper authentication mechanisms are essential to prevent unauthorized access and maintain system integrity.

Affected Version(s)

Email Protection Gateway 0 < 9.5.1

Email Protection Gateway 9.5.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Supr4s, https://yeswehack.com/hunters/supr4s
wlayzz, https://yeswehack.com/hunters/wlayzz
Icare, https://yeswehack.com/hunters/icare
truff, https://yeswehack.com/hunters/truff
.