Impact
The vulnerability is an identity‑verification flaw in the Kiteworks Email Protection Gateway. The gateway can perform actions on the underlying Kiteworks platform as if it were an authenticated user, even when no authentication has been performed. Additionally, the gateway can create a new platform account for an identity that the system did not previously recognise.
Affected Systems
Affected product is the Kiteworks Email Protection Gateway. No specific version information is provided; the flaw impacts all releases that contain the described identity‑verification weakness.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, so the current exploitation rate is unknown. The likely attack vector is a remote, unauthenticated sender transmitting traffic to the gateway, which may allow the attacker to gain control of a Kiteworks platform account or create a new account with elevated privileges.
OpenCVE Enrichment