Kiteworks patches max severity flaw in Email Protection Gateway enabling root takeover
Kiteworks fixed CVE-2026-54154, a CVSS 10 flaw chain in its Email Protection Gateway that could let unauthenticated attackers run code as root. Version 9.4.1 fixes it.
At a glance
- CVE-2026-54154 carries a CVSS v3.1 score of 10.0 and affects all Email Protection Gateway versions before 9.4.1.
- The flaw chains path traversal, code injection and missing authentication, allowing unauthenticated remote code execution and root control.
- The fix shipped as part of a release addressing 126 vulnerabilities across Kiteworks Core and EPG, according to BleepingComputer.
- CIS says there are no reports of exploitation in the wild; Kiteworks lists no workaround other than upgrading.
Kiteworks has patched a maximum severity vulnerability in its Email Protection Gateway (EPG) that could allow an unauthenticated remote attacker to execute arbitrary code and take full root control of the appliance. The flaw, tracked as CVE-2026-54154 and rated 10.0 on the CVSS v3.1 scale, was disclosed in a Kiteworks GitHub security advisory published on September 30, 2026, and reported by BleepingComputer on October 1. Because EPG sits at the edge of corporate email infrastructure and is often reachable from the internet, the bug is a high-value target for attackers.
What happened
According to the Kiteworks advisory, all Email Protection Gateway versions before 9.4.1 are affected, and the issue is fixed in 9.4.1 and later. The company said that a combination of input-handling flaws in publicly reachable EPG endpoints potentially allowed an unauthenticated remote attacker to achieve arbitrary code execution and, by chaining additional local weaknesses, to escalate to full administrative (root) control.
BleepingComputer reported that the fix is part of a larger security release addressing 126 vulnerabilities across Kiteworks Core and EPG components. Among them are 11 critical authentication bypass flaws, admin account takeover issues, stored cross-site scripting, improper access control and improper authentication weaknesses.
Technical details
The advisory lists three weakness classes behind CVE-2026-54154: path traversal (CWE-22), code injection (CWE-94) and missing authentication for a critical function (CWE-306). Its CVSS vector, AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, indicates a network-based attack of low complexity that needs no privileges or user interaction and can affect resources beyond the vulnerable component. Kiteworks said only that the issues were addressed with improved input validation and did not publish further technical detail.
The vulnerability was reported through Kiteworks' bug bounty program on YesWeHack; the advisory credits researchers wlayzz, icare and truff.
Who is affected
Any organization running a Kiteworks Email Protection Gateway release older than 9.4.1 is exposed. Kiteworks, formerly known as Accellion, serves thousands of corporations and government agencies, and its Private Content Network covers email, managed file transfer, file sharing, APIs and web forms, BleepingComputer noted. The outlet cited Shadowserver data showing roughly 400 Kiteworks instances exposed online, although it is unclear how many run EPG or remain unpatched.
The Center for Internet Security said in its October 1 advisory that there are currently no reports of the flaw being exploited in the wild, and it maps the issue to the MITRE ATT&CK technique for exploiting public-facing applications (T1190).
What to do
Administrators should upgrade Email Protection Gateway to 9.4.1 or later as soon as possible; the Kiteworks advisory does not list any workaround. CIS also recommends applying updates after appropriate testing, enforcing least privilege, and using network segmentation to limit exposure of management and public-facing services. Teams should review the full Kiteworks release to address the other critical authentication bypass and account takeover flaws in Core and EPG, and check logs on internet-facing appliances for unexpected activity.
Related CVEs
Sources
- Kiteworks patches max severity code injection vulnerability — BleepingComputer
- [EPG] Kiteworks Email Protection Gateway before version 9.4.1: Arbitrary code execution — Kiteworks (GitHub Security Advisory)
- A Vulnerability in Kiteworks EPG (Email Security Gateway) Could Allow for Arbitrary Code Execution — Center for Internet Security
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



