Dev.to Security 🔐 Cybersecurity 👁 0 📖 7 min read

Kiteworks EPG CVE-2026-54154: Pre-Auth RCE with Potential Root Escalation

1. Basic Information Original Title: [EPG] Kiteworks Email Protection Gateway before 9.4.1 is vulnerable to Improper Control of Generation of Code ('Code Injection') Source: Kiteworks Published Date: 2026-09-30 Update

1. Basic Information

  • Original Title: [EPG] Kiteworks Email Protection Gateway before 9.4.1 is vulnerable to Improper Control of Generation of Code ('Code Injection')
  • Source: Kiteworks
  • Published Date: 2026-09-30
  • Updated Date: None
  • Severity: Critical
  • Severity Basis: The CVSS v3.1 score is 10.0, with a network attack vector, low attack complexity, no privileges required, and no user interaction required. Arbitrary code execution could lead to root privileges if additional local weaknesses are successfully chained. The public advisory does not report exploitation in the wild. Because EPG deployments may be exposed to the internet, patching should be prioritized.
  • Original Link: Kiteworks security advisory
  • Related Sources: BleepingComputer, Kiteworks EPG: access control advisory (9.5.1), Kiteworks Core: stored XSS advisory (9.5.1)
  • Related Malware: None
  • Related Threat Groups: None
  • Related CVE: CVE-2026-54154
  • Related Products: Kiteworks Email Protection Gateway, Kiteworks Private Content Network

2. In Brief

According to Kiteworks, input-handling flaws in externally reachable EPG endpoints could allow unauthenticated remote attackers to execute arbitrary code on versions before 9.4.1. Escalation to root requires successfully chaining additional local weaknesses. This CVE was fixed in EPG 9.4.1.

3. Attack Flow

Flow 1: Chain from Public Endpoint to Root Privileges

  1. According to the vendor, unauthenticated attackers exploit an input handling flaw in a target endpoint of the EPG that is reachable from the outside. Specific request details have not been published.
  2. Due to the input handling flaw, arbitrary code may be executed on the appliance. CWE-22, CWE-94, and CWE-306 are assigned, but this classification alone does not determine the exact exploitation order of each weakness.
  3. If additional local weaknesses can be chained, full administrative (root) privileges are attained.

4. Attacker Positioning and Execution Location

  • The attacker is positioned with network reachability to the target EPG endpoint. Prior authentication and user interaction are not required.
  • Achieving root privileges requires chaining additional local weaknesses after arbitrary code execution.

5. Visibility for Victims and Administrators

Victims

  • No specific screen changes unique to regular users have been published. Operational anomalies in email delivery or gateways may occur, but no actual instances have been made public.

Administrators

  • Inference: If access logs, process creation audit logs, and configuration change histories are available, they may provide evidence of anomalous requests, child processes, and unauthorized administrative actions. Standard system logs may not capture all of these events. The vendor's public advisory lists no specific IoCs.

6. Success and Failure Conditions

Success Conditions

  • Attackers have network reachability to an affected version of EPG (prior to 9.4.1).
  • Crafted requests are processed by the public endpoint, and code injection succeeds.
  • Escalation to root privileges succeeds by chaining additional local weaknesses.

Failure Conditions

  • This CVE is fixed in EPG 9.4.1. Because other EPG vulnerabilities published on the same day are fixed in 9.5.1, do not assume 9.4.1 alone covers all advisories; verify the applied release and each fix.
  • Until updates are applied, isolate gateway management and target endpoints from the internet, restricting access to trusted sources.
  • Details of target endpoints and attack requests are unpublished, so WAFs cannot be guaranteed to block this CVE. Treat access restrictions as temporary mitigations and apply vendor patches.

7. Impact Upon Success

  • Unauthenticated arbitrary code execution.
  • Acquisition of root privileges through the chaining of additional local weaknesses.
  • Inference: Impacts on gateway configuration, credentials, encryption keys, and message processing are conceivable, but these are not confirmed in actual exploitation.

8. Observable Logs

Email

  • Check for sudden gaps in message tracking logs, unusual queue backlogs, and changes to delivery rules as supporting evidence.

Proxy / SWG / DNS

  • Check reverse proxies and WAFs in front of EPG for unknown source IPs, anomalous paths, and error or success responses.

Endpoint / EDR

  • If appliance telemetry is available, check for shells or utility launches from web processes, anomalous file creation, and privilege escalation.

Identity / IdP

  • Check for the creation, modification, or login of local administrator accounts on the EPG, as well as abnormal use of centrally managed accounts.

SaaS / Cloud

  • Check for configuration changes in the Kiteworks management console, updates to encryption keys or certificates, and connector modifications.

Network

  • Check for connections from unknown sources to the EPG and outbound traffic from the EPG to unknown destinations. Payload contents cannot be determined without HTTPS decryption.

9. Attack Success Determination

Confirm Malware Execution or Authentication Success

  • Public Information and Criteria: Public Information: The vendor explains the possibility of code execution, and no confirmation of active exploitation has been published. Criteria: RCE success is determined when attacker-derived code execution associated with the target request is confirmed via process or audit records. Scans, HTTP response codes, and unusual child processes alone are insufficient for confirmation.
  • Scope: Unauthenticated arbitrary code execution on Kiteworks EPG
  • Related CVE: CVE-2026-54154

Confirm Subsequent Compromise

  • Public Information and Criteria: Public Information: Escalation to root privileges is an impact resulting from chaining additional local weaknesses and is not an observation of actual compromise. Criteria: Confirm root-level execution or unauthorized configuration changes attributable to attacker actions using evidence. The presence of legitimate root processes or maintenance work alone does not constitute root compromise.
  • Scope: Root privileges on the EPG appliance
  • Related CVE: CVE-2026-54154

10. Investigation Playbook

Trigger

  • Initiate investigation based on affected versions, internet exposure, WAF alerts, suspicious process creation, and configuration changes.

Initial Verification

  • Check versions, exposure scope, patch application times, log retention status, unknown source IPs, and web response status.

Endpoints

  • Preserve appliance logs and available filesystem images, examining web process trees, files, cron jobs, services, and root-level operations.

Authentication and Cloud

  • Check local administrators, API tokens, connector credentials, and certificates, rotating them if any suspicion arises.

Subsequent Operations

  • Trace outbound traffic from EPG, email rule modifications, and operations targeting Kiteworks Core or connected systems.

Containment

  • Limit reachability and update to version 9.4.1 or later after preserving evidence. If compromise is confirmed, consider rebuilding and reissuing credentials and encryption keys.

Decision Categories

  • Record scans, RCE success, root attainment, and impact on data or credentials by stage.

11. Defense and Detection Ideas

Single Events

  • Prioritize the launch of shells, interpreters, and system utilities from web processes.

Timeline Correlation

  • Correlate anomalous requests from unknown sources -> child processes spawned by web processes -> root-level operations -> outbound traffic.

Hunting Perspective

  • Review the pre-update period for suspicious web requests, file creation, persistence mechanisms configured to run automatically, and changes to administrator accounts or encryption keys.

Log Gaps

  • Because public IoCs and endpoint details are lacking, request signatures alone are insufficient. When appliance telemetry is sparse, combine network, audit logs, and configuration diffs.

Priority Countermeasures

  • Prioritize updating to 9.4.1 or later, restricting external exposure, preserving logs, and verifying credentials and encryption keys.

12. Facts / Inference / Hypothesis

Facts

  • Kiteworks states that input-handling flaws in externally reachable EPG endpoints before version 9.4.1 could allow unauthenticated remote code execution. Escalation to root requires successfully chaining additional local weaknesses.
  • The CVSS v3.1 score for CVE-2026-54154 is 10.0, classified under CWE-22, CWE-94, and CWE-306. The fixed version is 9.4.1 and later.
  • Kiteworks states that reports were received through the YesWeHack bug bounty program. Public advisories do not report active exploitation or successful compromise in real-world environments, though this does not indicate an absence of exploitation.
  • Separate advisories published on the same day identify version 9.5.1 as the fix for an EPG access control flaw and a Kiteworks Core stored XSS vulnerability that could lead to administrator account takeover. These are separate issues from CVE-2026-54154, which was fixed in EPG 9.4.1.

Inference

  • If EPG is reachable from the internet, the risk of pre-auth RCE discovery and exploitation is high; prioritize external exposure restriction and log preservation prior to updates.
  • After attaining root privileges, impacts on gateway configurations, encryption keys, and message processing are possible, but public materials do not show post-compromise actions.

Hypothesis

No additional hypotheses. Unconfirmed items are noted in "14. Unknowns and Additional Investigation."

13. MITRE ATT&CK Mapping

ID Technique Confidence Basis
T1190 Exploit Public-Facing Application high The vendor explains the possibility of pre-authentication code execution from public endpoints. This is not an observation of active exploitation.
T1068 Exploitation for Privilege Escalation medium The vendor explains the possibility of root escalation via additional local weaknesses. Specific techniques and active exploitation are unconfirmed.

14. Unknowns and Additional Investigation

  • Details of vulnerable endpoints, request fields, and payload formats.
  • Presence of active exploitation, threat actors, and number of impacted organizations.
  • Scope of credentials, encryption keys, and message data accessible after obtaining root privileges.

15. Impact on SOCs and Organizations

Because email protection gateways sit at the network perimeter, patching should be accompanied by a retrospective review of management-interface exposure, unusual child processes spawned by web processes, and changes to configurations, encryption keys, and administrator accounts. Where EPG deployments in Japan connect to overseas gateways or centralized management systems, investigate whether trust relationships or shared credentials could allow a compromise to affect those connected environments.

16. Audience-Specific Summary

  • SOC: Preserve EPG web, audit, and system logs, correlating unknown sources, anomalous requests, command execution under web processes, root-level operations, and configuration or key changes.
  • Administrators: The fix level for this CVE is EPG 9.4.1. Check fix levels for other EPG vulnerabilities (9.5.1) to select update targets, and restrict external reachability until applied. Preserve logs and configurations, and evaluate the impact to reissue potentially compromised credentials and keys.
  • Users: No regular user action is required. Follow any instructions from administrators regarding email gateway maintenance or temporary suspensions.
📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.