---
id: CVE-2026-102130
title: >-
  Kiteworks Email Protection Gateway did not sufficiently validate the content
  of an uploaded backup, and allowed an administrator to influence how the
  application loaded it
summary: >-
  Kiteworks Email Protection Gateway did not sufficiently validate the content
  of an uploaded backup, and allowed an administrator to influence how the
  application loaded it. An authenticated administrator could potentially use
  this to exe…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-94
  - CWE-434
vendor: Kiteworks
product: Email Protection Gateway
affected:
  - email_protection_gateway < 9.5.1
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:17:01.533'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102130'
references:
  - url: >-
      https://github.com/kiteworks/security-advisories/security/advisories/GHSA-m92m-q8cf-rcch
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T21:25:07.832Z'
---

## Overview

Kiteworks Email Protection Gateway did not sufficiently validate the content of an uploaded backup, and allowed an administrator to influence how the application loaded it. An authenticated administrator could potentially use this to execute arbitrary code on the gateway as the underlying service account.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
