Server-Side Request Forgery in Kiteworks Email Protection Gateway
CVE-2026-102105

9.1CRITICAL

Key Information:

Vendor

Kiteworks

Vendor
CVE Published:
30 September 2026

What is CVE-2026-102105?

The Kiteworks Email Protection Gateway has a vulnerability that allows an unauthenticated remote attacker to exploit SSRF weaknesses. This can enable the attacker to craft requests that reach unintended internal network destinations when the gateway processes email content containing links to external resources. The impact of this vulnerability could result in the exposure of sensitive internal data or potentially trigger unauthorized actions within internal systems. Addressing this flaw is critical to maintaining the security of the affected environment.

Affected Version(s)

Email Protection Gateway 0 < 9.5.0

Email Protection Gateway 9.5.0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.