Description
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery. Kiteworks Email Protection Gateway performed server-side fetches of URLs contained in the message content it processed, without adequately restricting the fetch destination. A remote, unauthenticated sender could craft a message that caused the gateway to issue requests to internal services and cloud instance metadata endpoints and return the responses, potentially disclosing sensitive internal data and, depending on the internal service reached, affecting its state.
Published: 2026-09-30
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery
Action: Immediate Patch
AI Analysis

Impact

Kiteworks Email Protection Gateway before version 9.5.0 suffers a Server‑Side Request Forgery flaw. The gateway automatically fetches URLs embedded in inbound messages without validating their destination, allowing a remote, unauthenticated sender to craft a payload that causes the gateway to request internal services or cloud instance metadata endpoints. The returned content is then sent back to the attacker, potentially exposing sensitive internal data or altering the state of internal services.

Affected Systems

The vulnerability affects Kiteworks Email Protection Gateway deployments using any version earlier than 9.5.0. Operators of legacy installations should verify their product version; those on 9.5.0 or newer are not impacted.

Risk and Exploitability

The flaw carries a CVSS base score of 9.1, indicating a critical impact on confidentiality, integrity, and availability. No EPSS information is currently published, so the current exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog. Because the request originates from a remote send‑mail source, the attack vector is easily achievable; an attacker only needs to send a crafted message to the gateway, making this an unmitigated threat until mitigated.

Generated by OpenCVE AI on September 30, 2026 at 22:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Kiteworks Email Protection Gateway to version 9.5.0 or later.
  • Restrict outbound connections from the gateway to only approved external domains, effectively blocking internal or cloud metadata endpoints.
  • Monitor the gateway's outbound traffic for anomalous requests and block any unauthorized destinations.

Generated by OpenCVE AI on September 30, 2026 at 22:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Kiteworks
Kiteworks kiteworks Email Protection Gateway
Vendors & Products Kiteworks
Kiteworks kiteworks Email Protection Gateway

Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery. Kiteworks Email Protection Gateway performed server-side fetches of URLs contained in the message content it processed, without adequately restricting the fetch destination. A remote, unauthenticated sender could craft a message that caused the gateway to issue requests to internal services and cloud instance metadata endpoints and return the responses, potentially disclosing sensitive internal data and, depending on the internal service reached, affecting its state.
Title Kiteworks Email Protection Gateway server-side request forgery
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Kiteworks Kiteworks Email Protection Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-10-01T13:37:08.956Z

Reserved: 2026-09-28T17:39:13.561Z

Link: CVE-2026-102095

cve-icon Vulnrichment

Updated: 2026-10-01T13:32:32.185Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T21:16:56.120

Modified: 2026-10-01T14:17:13.173

Link: CVE-2026-102095

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:30:08Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)