Description
An identity-verification weakness in Kiteworks Email Protection Gateway allowed the gateway to act on the Kiteworks platform on behalf of a user it had not authenticated, and to provision a platform account for an identity it did not already know. A remote, unauthenticated sender could potentially exploit this to obtain control of a platform account.
Published: 2026-09-30
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Account Takeover
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is an identity‑verification flaw in the Kiteworks Email Protection Gateway. The gateway can perform actions on the underlying Kiteworks platform as if it were an authenticated user, even when no authentication has been performed. Additionally, the gateway can create a new platform account for an identity that the system did not previously recognise.

Affected Systems

Affected product is the Kiteworks Email Protection Gateway. No specific version information is provided; the flaw impacts all releases that contain the described identity‑verification weakness.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, so the current exploitation rate is unknown. The likely attack vector is a remote, unauthenticated sender transmitting traffic to the gateway, which may allow the attacker to gain control of a Kiteworks platform account or create a new account with elevated privileges.

Generated by OpenCVE AI on September 30, 2026 at 22:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor’s latest patch for the Email Protection Gateway that enforces proper identity verification before any state‑changing or account‑creation operation.
  • Configure the gateway to reject all unauthenticated or unauthenticated requests, ensuring only authenticated sessions can interact with the platform.
  • Enable role‑based access control and multi‑factor authentication on all Kiteworks platform accounts, and monitor logs for unauthorized account provisioning events.

Generated by OpenCVE AI on September 30, 2026 at 22:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Kiteworks
Kiteworks kiteworks Email Protection Gateway
Vendors & Products Kiteworks
Kiteworks kiteworks Email Protection Gateway

Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description An identity-verification weakness in Kiteworks Email Protection Gateway allowed the gateway to act on the Kiteworks platform on behalf of a user it had not authenticated, and to provision a platform account for an identity it did not already know. A remote, unauthenticated sender could potentially exploit this to obtain control of a platform account.
Title Kiteworks Email Protection Gateway Improper Authentication
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Kiteworks Kiteworks Email Protection Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-10-01T13:37:05.460Z

Reserved: 2026-09-28T17:39:13.563Z

Link: CVE-2026-102128

cve-icon Vulnrichment

Updated: 2026-10-01T13:32:03.366Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T21:17:01.270

Modified: 2026-10-01T14:17:17.143

Link: CVE-2026-102128

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:30:08Z

Weaknesses