Server-Side Request Forgery Vulnerability in Kiteworks Email Protection Gateway
CVE-2026-102095

9.1CRITICAL

Key Information:

Vendor

Kiteworks

Vendor
CVE Published:
30 September 2026

What is CVE-2026-102095?

The Kiteworks Email Protection Gateway prior to version 9.5.0 is susceptible to a Server-Side Request Forgery (SSRF) attack. This vulnerability allows a malicious remote sender to manipulate email content in such a way that the gateway processes requests to internal services or cloud instance metadata endpoints. Such actions may lead to unauthorized data disclosure and could influence the operational state of these internal services, creating potential security risks for sensitive internal data.

Affected Version(s)

Email Protection Gateway 0 < 9.5.0

Email Protection Gateway 9.5.0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

truff, https://yeswehack.com/hunters/truff
Icare, https://yeswehack.com/hunters/icare
wlayzz, https://yeswehack.com/hunters/wlayzz
.