Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-102131 Details

Description

Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did not recognize every form in which they could be supplied. An authenticated administrator could potentially use an unrecognized form to have a file of their choosing written to the gateway and executed, resulting in code execution as the gateway service account.

Metrics

CVSS 3.x Severity and Vector Strings:

CNA: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian GovernmentCVSS-B:7.2 HIGHVector:CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://github.com/kiteworks/security-advisories/security/advisories/GHSA-62f6-c955-4fhq Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government
https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Weakness Enumeration

CWE-IDCWE NameSource
CWE-178Improper Handling of Case SensitivityCybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government
CWE-94Improper Control of Generation of Code ('Code Injection')Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Affected Products

No affected product data is available for this CVE.

Change History

1 change record found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-102131
NVD Published Date:
Sep 30, 2026
NVD Last Modified:
Oct 1, 2026
Source:
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government
CVE-2026-102131 Details - Not Deferred