XML Parsing Vulnerability in Kiteworks Email Protection Gateway
CVE-2026-102127

7HIGH

Key Information:

Vendor

Kiteworks

Vendor
CVE Published:
30 September 2026

What is CVE-2026-102127?

The Kiteworks Email Protection Gateway contains an XML parser vulnerability that allows external entity references to be unchecked. This flaw can be exploited when a specific, non-default message-processing feature is enabled. A remote, unauthenticated attacker could craft a specially designed message to gain access to files that the gateway service account can access. This may include sensitive information such as cryptographic keys and credentials, which could then be exfiltrated to an external location under the attacker's control.

Affected Version(s)

Email Protection Gateway 0 < 9.5.1

Email Protection Gateway 9.5.1

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.