Search
Search Results (4 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-102144 | 1 Kiteworks | 1 Kiteworks Email Protection Gateway | 2026-10-01 | 5.3 Medium |
| A resource exhaustion vulnerability in Kiteworks Email Protection Gateway allowed an unauthenticated remote attacker to repeatedly trigger a comparatively expensive server-side operation, causing a partial denial of service. | ||||
| CVE-2026-102143 | 1 Kiteworks | 1 Kiteworks Email Protection Gateway | 2026-10-01 | 7.5 High |
| An unauthenticated attacker could cause a file with attacker-controlled content to be written to the appliance filesystem through an administrative upload handler that did not properly authenticate the request. This did not by itself result in code execution, which would require a separate vulnerability to place the file in an executable location. | ||||
| CVE-2026-102116 | 1 Kiteworks | 1 Kiteworks Email Protection Gateway | 2026-10-01 | 7.2 High |
| -A weakness could have allowed an authenticated Kiteworks Email Protection Gateway administrator to write a file outside its intended location and cause the application to execute it, potentially resulting in remote code execution as the underlying service account. | ||||
| CVE-2026-29092 | 2 Accellion, Kiteworks | 2 Kiteworks, Kiteworks Email Protection Gateway | 2026-03-29 | 4.9 Medium |
| Kiteworks is a private data network (PDN). Prior to version 9.2.1, a vulnerability in Kiteworks Email Protection Gateway session management allows blocked users to maintain active sessions after their account is disabled. This could allow unauthorized access to continue until the session naturally expires. Upgrade Kiteworks to version 9.2.1 or later to receive a patch. | ||||
Page 1 of 1.