---
id: CVE-2026-102119
title: >-
  A path traversal weakness in an optional, non-default administrative feature
  allowed an authenticated administrator to move files to unintended locations
  outside the feature's designated directory
summary: >-
  A path traversal weakness in an optional, non-default administrative feature
  allowed an authenticated administrator to move files to unintended locations
  outside the feature's designated directory. This could potentially be
  leveraged to …
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
vendor: Kiteworks
product: Email Protection Gateway
affected:
  - email_protection_gateway < 9.5.0
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:16:59.900'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102119'
references:
  - url: >-
      https://github.com/kiteworks/security-advisories/security/advisories/GHSA-3r3r-hp4c-pxmh
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T21:25:07.828Z'
---

## Overview

A path traversal weakness in an optional, non-default administrative feature allowed an authenticated administrator to move files to unintended locations outside the feature's designated directory. This could potentially be leveraged to execute arbitrary code on the underlying system.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
