Server-Side Request Forgery Vulnerability in Kiteworks Email Protection Gateway
CVE-2026-102104
9.1CRITICAL
What is CVE-2026-102104?
The Kiteworks Email Protection Gateway prior to version 9.5.0 has a vulnerability that allows remote, unauthorized users to exploit the system through server-side request forgery (SSRF). This weakness can lead to the gateway sending unauthorized requests to internal or unintended network locations when processing online certificate status checks. If exploited, this could potentially disclose sensitive internal information or disrupt the operation of the gateway.
Affected Version(s)
Email Protection Gateway 0 < 9.5.0
Email Protection Gateway 9.5.0
