Description
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway retrieves a certificate revocation list in an inbound message. Depending on the services reachable from the gateway, this could disclose sensitive internal information or disrupt gateway operation.
Published: 2026-09-30
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Server‑Side Request Forgery (SSRF) that allows an unauthenticated attacker to trigger the gateway to make arbitrary outbound requests
Action: Patch ASAP
AI Analysis

Impact

Kiteworks Email Protection Gateway versions before 9.5.0 contain an SSRF weakness. The vulnerability is exercised while the gateway fetches a certificate revocation list from an inbound message; a crafted request can cause the gateway to issue requests to internal or otherwise unintended network destinations. The attacker gains the ability to read sensitive internal data or disrupt gateway operation, but does not achieve local code execution on the gateway itself. This flaw is identified as CWE‑918.

Affected Systems

The affected product is Kiteworks Email Protection Gateway. All releases older than version 9.5.0 are impacted. No further details on patch levels are provided.

Risk and Exploitability

The CVSS score of 9.1 categorizes the issue as high‑severity. Because the vulnerability allows arbitrary outbound traffic, it can be leveraged against any service reachable from the gateway, potentially exposing internal addresses and data. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that no publicly known exploits are currently documented. The likely attack vector is via a crafted inbound email that triggers CRL retrieval, thus requiring the attacker to be able to send such an email to the gateway.

Generated by OpenCVE AI on September 30, 2026 at 21:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Kiteworks Email Protection Gateway to version 9.5.0 or later, which removes the SSRF flaw
  • If immediate upgrade is not possible, block outbound HTTP/HTTPS traffic originating from the gateway to internal IP ranges or restrict the CRL retrieval endpoint to trusted URLs
  • Continuously monitor gateway logs for unexpected outbound requests and enforce strict input validation on incoming email attachments and metadata

Generated by OpenCVE AI on September 30, 2026 at 21:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Kiteworks
Kiteworks kiteworks Email Protection Gateway
Vendors & Products Kiteworks
Kiteworks kiteworks Email Protection Gateway

Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway retrieves a certificate revocation list in an inbound message. Depending on the services reachable from the gateway, this could disclose sensitive internal information or disrupt gateway operation.
Title Kiteworks Email Protection Gateway server-side request forgery
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Subscriptions

Kiteworks Kiteworks Email Protection Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-10-01T13:37:04.650Z

Reserved: 2026-09-28T17:39:13.561Z

Link: CVE-2026-102103

cve-icon Vulnrichment

Updated: 2026-10-01T13:31:56.513Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T21:16:57.127

Modified: 2026-10-01T14:17:14.043

Link: CVE-2026-102103

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:30:08Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)