---
id: CVE-2026-102146
title: >-
  An authenticated Email Protection Gateway administrator holding only limited,
  delegated permissions could write files with attacker-controlled content to
  arbitrary locations accessible to the Email Protection Gateway service account
summary: >-
  An authenticated Email Protection Gateway administrator holding only limited,
  delegated permissions could write files with attacker-controlled content to
  arbitrary locations accessible to the Email Protection Gateway service
  account. Thi…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-73
vendor: Kiteworks
product: Email Protection Gateway
affected:
  - email_protection_gateway < 9.5.1
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:17:03.510'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102146'
references:
  - url: >-
      https://github.com/kiteworks/security-advisories/security/advisories/GHSA-5pgq-v8g2-rg2f
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T21:25:07.837Z'
---

## Overview

An authenticated Email Protection Gateway administrator holding only limited, delegated permissions could write files with attacker-controlled content to arbitrary locations accessible to the Email Protection Gateway service account. This exceeds the administrator's intended privileges and could be used to alter application files and configuration or to disrupt the availability of the service.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
