Full Report
Secure file-sharing software company Kiteworks has released security updates to address 126 vulnerabilities, including a max-severity flaw affecting its Email Protection Gateway (EPG) security solution. [...]
Analysis Summary
# Vulnerability: Kiteworks EPG Path Traversal and Code Injection
## CVE Details
- **CVE ID:** CVE-2026-54154
- **CVSS Score:** 10.0 (Critical)
- **CWE:** Chain of Path Traversal, Code Injection, and Missing Authentication.
## Affected Systems
- **Products:** Kiteworks Email Protection Gateway (EPG)
- **Versions:** All releases prior to version 9.4.1.
- **Configurations:** Systems with publicly reachable endpoints enabled.
## Vulnerability Description
CVE-2026-54154 is a maximum-severity vulnerability resulting from a combination of input-handling flaws in publicly reachable endpoints. An unauthenticated remote attacker can exploit a chain of path traversal and code injection vulnerabilities. By further chaining these with local weaknesses, the attacker can achieve arbitrary code execution (RCE) and escalate privileges to full administrative (root) control of the EPG appliance.
## Exploitation
- **Status:** Not explicitly reported as exploited in the wild (though a precautionary shutdown was previously issued due to threat intelligence of an "imminent" attack). No public PoC currently available.
- **Complexity:** Low
- **Attack Vector:** Network (Remote)
- **User Interaction:** None Required
## Impact
- **Confidentiality:** High (Full administrative access allows access to all stored data/emails)
- **Integrity:** High (Attacker can modify system files and configurations)
- **Availability:** High (Potential for complete system takeover or shutdown)
## Remediation
### Patches
- **Kiteworks EPG:** Update to version **9.4.1** or later immediately.
- **Kiteworks Core:** Apply the latest security updates released alongside EPG 9.4.1 to address 125 additional vulnerabilities, including critical authentication bypasses.
### Workarounds
- No specific software workarounds were provided; however, Kiteworks previously recommended a temporary server shutdown for hosted/on-prem systems until patches could be verified and applied.
## Detection
- **Indicators of Compromise:** Look for unusual activity in EPG logs, specifically unauthorized access to publicly reachable endpoints or evidence of path traversal attempts (e.g., `../` sequences in request logs).
- **Detection methods and tools:** Kiteworks stated they found no evidence of compromise in their hosted systems; customers should perform internal audits of root-level activities and system integrity. Use external scanners to identify exposed Kiteworks instances via services like Shadowserver.
## References
- Kiteworks Security Advisory: hxxps[://]github[.]com/kiteworks/security-advisories/security/advisories/GHSA-5xhq-9wq3-rvj6
- Full Advisory List: hxxps[://]github[.]com/kiteworks/security-advisories/security
- Shadowserver Kiteworks Statistics: hxxps[://]dashboard[.]shadowserver[.]org/statistics/iot-devices/time-series/?date_range=other_range&d1=2026-09-26&d2=2026-09-27&vendor=kiteworks&type=other-software&model=kiteworks&limit=100&group_by=geo&stacking=stacked