Impact
The vulnerability is an authorization bypass in the large file exchange feature of Kiteworks Email Protection Gateway. An authenticated user can read the subject, message body, and attachments of packages that they neither sent nor received. This flaw allows an attacker to gain confidential email content that is not meant for them, potentially revealing sensitive business information and violating privacy regulations.
Affected Systems
The affected system is Kiteworks Email Protection Gateway. No specific version information is provided in the advisory, so all deployed instances could be impacted until a vendor update is applied.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. Because the flaw requires an authenticated session, an attacker must first obtain valid credentials or gain access to an existing account. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that there is no known public exploitation yet. Nonetheless, the potential for unauthorized disclosure warrants proactive remediation.
OpenCVE Enrichment