Description
An XML parser used by Kiteworks Email Protection Gateway did not restrict external entity references. Where an optional, non-default message-processing feature is enabled, a remote and unauthenticated sender could potentially use a crafted message to read files accessible to the gateway service account, including cryptographic key material and credentials, and have them sent to a destination they control.
Published: 2026-09-30
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure through XML external entity processing
Action: Immediate Patch
AI Analysis

Impact

An XML parser in Kiteworks Email Protection Gateway does not restrict external XML entity references. When the optional message‑processing feature is enabled, an unauthenticated sender can craft a message with a malicious XML payload that forces the gateway to resolve external entities. This allows the gateway service account to read arbitrary files, including cryptographic keys and credentials, and forward them to an attacker‑controlled address, thereby compromising sensitive data.

Affected Systems

All installations of Kiteworks Email Protection Gateway that have the optional message‑processing feature enabled. No specific version ranges are published, so any release containing the feature may be vulnerable.

Risk and Exploitability

The CVSS base score of 7 indicates high severity. Exploitation requires only remote delivery of a crafted message and does not need authentication. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the high score and remote unauthenticated nature mean the risk is substantial, especially for systems with the feature active and exposed to untrusted email. Reducing the attack surface by disabling the feature or mitigating XML parsing can lower the threat level.

Generated by OpenCVE AI on September 30, 2026 at 22:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Disable the optional message‑processing feature that processes XML on the gateway to prevent external entity resolution.
  • Configure the gateway to reject or sanitize XML documents containing external entity references before they reach the vulnerable parser.
  • Apply the vendor‑supplied patch or upgrade Kiteworks Email Protection Gateway to a version that fixes the XML parsing issue as soon as it becomes available.

Generated by OpenCVE AI on September 30, 2026 at 22:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Kiteworks
Kiteworks kiteworks Email Protection Gateway
Vendors & Products Kiteworks
Kiteworks kiteworks Email Protection Gateway

Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description An XML parser used by Kiteworks Email Protection Gateway did not restrict external entity references. Where an optional, non-default message-processing feature is enabled, a remote and unauthenticated sender could potentially use a crafted message to read files accessible to the gateway service account, including cryptographic key material and credentials, and have them sent to a destination they control.
Title Kiteworks Email Protection Gateway Improper Restriction of XML External Entity Reference
Weaknesses CWE-611
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L'}


Subscriptions

Kiteworks Kiteworks Email Protection Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-10-01T13:37:05.291Z

Reserved: 2026-09-28T17:39:13.563Z

Link: CVE-2026-102127

cve-icon Vulnrichment

Updated: 2026-10-01T13:32:01.168Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T21:17:01.117

Modified: 2026-10-01T14:17:17.020

Link: CVE-2026-102127

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:30:08Z

Weaknesses
  • CWE-611

    Improper Restriction of XML External Entity Reference