Unsafe Reflection Vulnerability in Kiteworks Email Protection Gateway
CVE-2026-102094

7.2HIGH

Key Information:

Vendor

Kiteworks

Vendor
CVE Published:
30 September 2026

What is CVE-2026-102094?

The Kiteworks Email Protection Gateway prior to version 9.5.0 is susceptible to an unsafe reflection vulnerability that fails to properly restrict the code that can be executed from an imported rule configuration. This flaw allows an authenticated administrator with mail-rule configuration privileges to manipulate the gateway into loading and executing unauthorized code beyond the sanctioned set of mail-processing components. As a result, this could lead to potential exploitation within the context of the mail-gateway service account, posing significant security risks.

Affected Version(s)

Email Protection Gateway 0 < 9.5.0

Email Protection Gateway 9.5.0

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.