Description
An authorization check in the large file exchange feature of Kiteworks Email Protection Gateway did not correctly establish that the requesting user was a party to the package being requested. An authenticated user of that optional feature could read the subject, message body, and attachments of packages they neither sent nor received.
Published: 2026-09-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch ASAP
AI Analysis

Impact

The vulnerability is an authorization bypass in the large file exchange feature of Kiteworks Email Protection Gateway. An authenticated user can read the subject, message body, and attachments of packages that they neither sent nor received. This flaw allows an attacker to gain confidential email content that is not meant for them, potentially revealing sensitive business information and violating privacy regulations.

Affected Systems

The affected system is Kiteworks Email Protection Gateway. No specific version information is provided in the advisory, so all deployed instances could be impacted until a vendor update is applied.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. Because the flaw requires an authenticated session, an attacker must first obtain valid credentials or gain access to an existing account. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that there is no known public exploitation yet. Nonetheless, the potential for unauthorized disclosure warrants proactive remediation.

Generated by OpenCVE AI on September 30, 2026 at 22:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch or upgrade to a version that fixes the authorization check in the large file exchange feature.
  • If immediate patching is not possible, restrict or disable the large file exchange capability for users who do not have a legitimate need to use it.
  • Review and tighten access controls for the Email Protection Gateway, ensuring that only authorized senders and recipients can access package contents.

Generated by OpenCVE AI on September 30, 2026 at 22:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Kiteworks
Kiteworks kiteworks Email Protection Gateway
Vendors & Products Kiteworks
Kiteworks kiteworks Email Protection Gateway

Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description An authorization check in the large file exchange feature of Kiteworks Email Protection Gateway did not correctly establish that the requesting user was a party to the package being requested. An authenticated user of that optional feature could read the subject, message body, and attachments of packages they neither sent nor received.
Title Kiteworks Email Protection Gateway Incorrect Authorization
Weaknesses CWE-639
CWE-863
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Kiteworks Kiteworks Email Protection Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-10-01T13:37:07.509Z

Reserved: 2026-09-28T17:39:13.564Z

Link: CVE-2026-102139

cve-icon Vulnrichment

Updated: 2026-10-01T13:32:20.311Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T21:17:02.663

Modified: 2026-10-01T14:17:18.493

Link: CVE-2026-102139

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:30:08Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key

  • CWE-863

    Incorrect Authorization