cbcvebase.
CVE-2026-102143
published 2026-09-30

CVE-2026-102143: An unauthenticated attacker could cause a file with attacker-controlled content to be written to the appliance filesystem through an administrative upload…

PriorityP351high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.32%
23.1th percentile
An unauthenticated attacker could cause a file with attacker-controlled content to be written to the appliance filesystem through an administrative upload handler that did not properly authenticate the request. This did not by itself result in code execution, which would require a separate vulnerability to place the file in an executable location.

Affected

1 ranges
VendorProductVersion rangeFixed in
kiteworksemail_protection_gateway< 9.5.19.5.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.