CVE-2026-102144

Summary

A resource exhaustion vulnerability in Kiteworks Email Protection Gateway allowed an unauthenticated remote attacker to repeatedly trigger a comparatively expensive server-side operation, causing a partial denial of service.

Affected Software

VendorProductVersion RangeStatus
KiteworksEmail Protection Gateway0 < 9.5.1affected
KiteworksEmail Protection Gateway9.5.1unaffected

Weaknesses

  • CWE-306: CWE-306 Missing Authentication for Critical Function
  • CWE-400: CWE-400 Uncontrolled Resource Consumption

References