---
id: CVE-2026-102089
title: >-
  Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to a
  path traversal weakness in an administrative import function allowed an
  authenticated administrator to write files to arbitrary locations on the
  server
summary: >-
  Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to a
  path traversal weakness in an administrative import function allowed an
  authenticated administrator to write files to arbitrary locations on the
  server. This coul…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
vendor: Kiteworks
product: Email Protection Gateway
affected:
  - email_protection_gateway < 9.5.0
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:16:55.350'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102089'
references:
  - url: >-
      https://github.com/kiteworks/security-advisories/security/advisories/GHSA-p853-p65q-2vc8
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T21:25:07.819Z'
---

## Overview

Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to a path traversal weakness in an administrative import function allowed an authenticated administrator to write files to arbitrary locations on the server. This could potentially be leveraged to execute arbitrary code on the underlying system.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
