Improper Authentication in Kiteworks Email Protection Gateway
CVE-2026-102106

9.1CRITICAL

Key Information:

Vendor

Kiteworks

Vendor
CVE Published:
30 September 2026

What is CVE-2026-102106?

The Kiteworks Email Protection Gateway contains a vulnerability in its administrative service that may allow unauthorized access due to inconsistent enforcement of administrator authentication. An attacker aware of a valid administrator account could bypass necessary password checks, enabling them to create, modify, or delete internal users and managed domains. This could result in unauthorized changes to security configurations, as well as the potential deletion of a managed domain, which may lock legitimate administrators out of the gateway, posing severe risks to the integrity of the system.

Affected Version(s)

Email Protection Gateway 0 < 9.5.0

Email Protection Gateway 9.5.0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.