CVE-2026-102128

Summary

An identity-verification weakness in Kiteworks Email Protection Gateway allowed the gateway to act on the Kiteworks platform on behalf of a user it had not authenticated, and to provision a platform account for an identity it did not already know. A remote, unauthenticated sender could potentially exploit this to obtain control of a platform account.

Affected Software

VendorProductVersion RangeStatus
KiteworksEmail Protection Gateway0 < 9.5.1affected
KiteworksEmail Protection Gateway9.5.1unaffected

Weaknesses

  • CWE-287: CWE-287 Improper Authentication

References