---
id: CVE-2026-102131
title: >-
  Kiteworks Email Protection Gateway rejected certain configuration settings,
  but its validation did not recognize every form in which they could be
  supplied
summary: >-
  Kiteworks Email Protection Gateway rejected certain configuration settings,
  but its validation did not recognize every form in which they could be
  supplied. An authenticated administrator could potentially use an unrecognized
  form to hav…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-94
  - CWE-178
vendor: Kiteworks
product: Email Protection Gateway
affected:
  - email_protection_gateway < 9.5.0
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:17:01.667'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102131'
references:
  - url: >-
      https://github.com/kiteworks/security-advisories/security/advisories/GHSA-62f6-c955-4fhq
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T21:25:07.832Z'
---

## Overview

Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did not recognize every form in which they could be supplied. An authenticated administrator could potentially use an unrecognized form to have a file of their choosing written to the gateway and executed, resulting in code execution as the gateway service account.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
