Impact
Kiteworks Email Protection Gateway before version 9.5.0 suffers a Server‑Side Request Forgery flaw. The gateway automatically fetches URLs embedded in inbound messages without validating their destination, allowing a remote, unauthenticated sender to craft a payload that causes the gateway to request internal services or cloud instance metadata endpoints. The returned content is then sent back to the attacker, potentially exposing sensitive internal data or altering the state of internal services.
Affected Systems
The vulnerability affects Kiteworks Email Protection Gateway deployments using any version earlier than 9.5.0. Operators of legacy installations should verify their product version; those on 9.5.0 or newer are not impacted.
Risk and Exploitability
The flaw carries a CVSS base score of 9.1, indicating a critical impact on confidentiality, integrity, and availability. No EPSS information is currently published, so the current exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog. Because the request originates from a remote send‑mail source, the attack vector is easily achievable; an attacker only needs to send a crafted message to the gateway, making this an unmitigated threat until mitigated.
OpenCVE Enrichment