---
id: CVE-2026-102143
title: >-
  An unauthenticated attacker could cause a file with attacker-controlled
  content to be written to the appliance filesystem through an administrative
  upload handler that did not properly authenticate the request
summary: >-
  An unauthenticated attacker could cause a file with attacker-controlled
  content to be written to the appliance filesystem through an administrative
  upload handler that did not properly authenticate the request. This did not by
  itself res…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-306
  - CWE-434
vendor: Kiteworks
product: Email Protection Gateway
affected:
  - email_protection_gateway < 9.5.1
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:17:03.143'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102143'
references:
  - url: >-
      https://github.com/kiteworks/security-advisories/security/advisories/GHSA-3p9g-jh62-8f89
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T21:25:07.836Z'
---

## Overview

An unauthenticated attacker could cause a file with attacker-controlled content to be written to the appliance filesystem through an administrative upload handler that did not properly authenticate the request. This did not by itself result in code execution, which would require a separate vulnerability to place the file in an executable location.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
