Server-Side Request Forgery in Kiteworks Email Protection Gateway
CVE-2026-102102

9.1CRITICAL

Key Information:

Vendor

Kiteworks

Vendor
CVE Published:
30 September 2026

What is CVE-2026-102102?

The Kiteworks Email Protection Gateway prior to version 9.5.0 contains a vulnerability that allows a remote and unauthenticated attacker to exploit server-side request forgery (SSRF). This could enable malicious requests to be sent to internal or unintended network locations while the gateway fetches issuer certificates for incoming messages. This exploitation risks exposure of sensitive internal data or potential disruptions to the operation of the gateway.

Affected Version(s)

Email Protection Gateway 0 < 9.5.0

Email Protection Gateway 9.5.0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.