Account Misconfiguration in Kiteworks Email Protection Gateway
CVE-2026-102149

9.4CRITICAL

Key Information:

Vendor

Kiteworks

Vendor
CVE Published:
30 September 2026

What is CVE-2026-102149?

The Kiteworks Email Protection Gateway has a vulnerability that allows insufficient restrictions on certificate assignment, which may enable an attacker to link a certificate to a different user's account. This flaw can compromise the confidentiality and integrity of encrypted emails, and if certificate-based login is active, it can grant unauthorized access to the affected account. Organizations using this product should promptly review their configurations and apply necessary safeguards.

Affected Version(s)

Email Protection Gateway 0 < 9.5.1

Email Protection Gateway 9.5.1

References

CVSS V3.1

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.