Description
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway retrieves an issuer certificate in an inbound message. Depending on the services reachable from the gateway, this could disclose sensitive internal information or disrupt gateway operation.
Published: 2026-09-30
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery
Action: Immediate Patch
AI Analysis

Impact

A server‑side request forgery flaw exists in Kiteworks Email Protection Gateway prior to version 9.5.0. The vulnerability is triggered when the gateway retrieves an issuer certificate from an inbound message. An attacker who can send a crafted inbound message can cause the gateway to issue HTTP requests to internal or otherwise unintended network destinations. This could enable the disclosure of sensitive internal information or cause disruption of gateway operation.

Affected Systems

Kiteworks Email Protection Gateway. All installations running any version earlier than 9.5.0 are affected.

Risk and Exploitability

The CVSS score of 9.1 indicates that remote attackers can achieve significant impact without authentication. While an EPSS score is not available, the lack of authentication requirements and the potential for internal data leakage or service disruption make the risk high. The vulnerability is not currently listed in the CISA KEV catalog, but the severity and the possible attack path involve a remote, unauthenticated attacker exploiting the gateway’s request‑sending behavior to reach internal resources.

Generated by OpenCVE AI on September 30, 2026 at 22:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Kiteworks Email Protection Gateway to version 9.5.0 or later.
  • Configure outbound network restrictions so the gateway cannot reach internal services through arbitrary URLs.
  • Monitor gateway logs for anomalous outbound requests and investigate any suspicious activity.

Generated by OpenCVE AI on September 30, 2026 at 22:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Kiteworks
Kiteworks kiteworks Email Protection Gateway
Vendors & Products Kiteworks
Kiteworks kiteworks Email Protection Gateway

Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway retrieves an issuer certificate in an inbound message. Depending on the services reachable from the gateway, this could disclose sensitive internal information or disrupt gateway operation.
Title Kiteworks Email Protection Gateway server-side request forgery
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Subscriptions

Kiteworks Kiteworks Email Protection Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-10-01T13:37:06.475Z

Reserved: 2026-09-28T17:39:13.561Z

Link: CVE-2026-102102

cve-icon Vulnrichment

Updated: 2026-10-01T13:32:11.504Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T21:16:57.000

Modified: 2026-10-01T14:17:13.923

Link: CVE-2026-102102

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:30:08Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)