---
id: CVE-2026-102097
title: >-
  Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to
  Remote Code Execution
summary: >-
  Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to
  Remote Code Execution. Kiteworks Email Protection Gateway allowed an
  authenticated administrator to import configuration whose contents were not
  sufficiently valida…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
  - CWE-94
vendor: Kiteworks
product: Email Protection Gateway
affected:
  - email_protection_gateway < 9.5.0
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:16:56.370'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102097'
references:
  - url: >-
      https://github.com/kiteworks/security-advisories/security/advisories/GHSA-465g-wpvm-8qmr
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T21:25:07.821Z'
---

## Overview

Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Remote Code Execution. Kiteworks Email Protection Gateway allowed an authenticated administrator to import configuration whose contents were not sufficiently validated before being processed. A crafted submission could potentially allow arbitrary commands to be executed on the affected gateway.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
