File Write Vulnerability in Email Protection Gateway from Kiteworks
CVE-2026-102146
6.5MEDIUM
What is CVE-2026-102146?
An authenticated administrator of the Email Protection Gateway with limited delegated permissions can write files containing attacker-controlled content to arbitrary locations accessible by the Email Protection Gateway service account. This vulnerability allows for potential alterations to application files, configurations, or even disruption of service availability, as the actions exceed the intended constraints of the administrator's permissions.
Affected Version(s)
Email Protection Gateway 0 < 9.5.1
Email Protection Gateway 9.5.1
