Answer in brief
CVE-2026-102146 records a Medium severity (CVSS 6.5) vulnerability in Kiteworks Email Protection Gateway Arbitrary File Write through Server-Side Template Injection. The current sources do not mark it as known exploited. The current feed maps Kiteworks/Email Protection Gateway (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 6.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Kiteworks/Email Protection Gateway (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Kiteworks/Email Protection Gatewaygeneric | >=0 <9.5.1 | 9.5.1 |
Published upstream
Sep 30, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 1, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 30, 2026
An authenticated Email Protection Gateway administrator holding only limited, delegated permissions could write files with attacker-controlled content to arbitrary locations accessible to the Email Protection Gateway service account. This exceeds the administrator's intended privileges and could be used to alter application files and configuration or to disrupt the availability of the service.
Quoted source text, attributed separately from HOL analysis.