Unsafe Reflection Vulnerability in Kiteworks Email Protection Gateway
CVE-2026-102094
7.2HIGH
What is CVE-2026-102094?
The Kiteworks Email Protection Gateway prior to version 9.5.0 is susceptible to an unsafe reflection vulnerability that fails to properly restrict the code that can be executed from an imported rule configuration. This flaw allows an authenticated administrator with mail-rule configuration privileges to manipulate the gateway into loading and executing unauthorized code beyond the sanctioned set of mail-processing components. As a result, this could lead to potential exploitation within the context of the mail-gateway service account, posing significant security risks.
Affected Version(s)
Email Protection Gateway 0 < 9.5.0
Email Protection Gateway 9.5.0
