Improper Authentication in Kiteworks Email Protection Gateway
CVE-2026-102106
9.1CRITICAL
What is CVE-2026-102106?
The Kiteworks Email Protection Gateway contains a vulnerability in its administrative service that may allow unauthorized access due to inconsistent enforcement of administrator authentication. An attacker aware of a valid administrator account could bypass necessary password checks, enabling them to create, modify, or delete internal users and managed domains. This could result in unauthorized changes to security configurations, as well as the potential deletion of a managed domain, which may lock legitimate administrators out of the gateway, posing severe risks to the integrity of the system.
Affected Version(s)
Email Protection Gateway 0 < 9.5.0
Email Protection Gateway 9.5.0
