Description
Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could be assigned to. This could allow an attacker to associate a certificate with another user's account, affecting the confidentiality and integrity of that account's encrypted mail and, where certificate-based login is enabled, potentially permitting unauthorized access to the account.
Published: 2026-09-30
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access to Accounts and Confidentiality of Encrypted Mail
Action: Immediate Patch
AI Analysis

Impact

The Kiteworks Email Protection Gateway fails to enforce restrictions on which account a certificate may be assigned to. An attacker can thus associate a certificate with a different user’s account, compromising the confidentiality and integrity of that account’s encrypted mail. If certificate-based login is enabled, the compromised account can be accessed without legitimate credentials.

Affected Systems

Kiteworks Email Protection Gateway from Kiteworks. No specific product versions are listed in the advisories, so all released builds may be affected until a patch is applied.

Risk and Exploitability

The CVSS score is 9.4, indicating critical severity. EPSS is not available, so the likelihood of exploitation cannot be quantified, but the absence of a KEV listing does not diminish the potential impact. Based on the description, it is inferred that the vulnerability can be exercised through the gateway’s certificate management functions. The likely attack vector is any authenticated session that has rights to create certificates, through which an attacker can redirect a valid certificate to a target account and gain unauthorized access to that account’s encrypted communications and possibly its login session.

Generated by OpenCVE AI on September 30, 2026 at 22:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Kiteworks Email Protection Gateway update once released by Kiteworks.
  • Revoke all certificates that may have been incorrectly assigned and issue new certificates to the affected accounts.
  • Restrict certificate assignment privileges to a minimal set of administrators and review role-based access controls.

Generated by OpenCVE AI on September 30, 2026 at 22:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Kiteworks
Kiteworks kiteworks Email Protection Gateway
Vendors & Products Kiteworks
Kiteworks kiteworks Email Protection Gateway

Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could be assigned to. This could allow an attacker to associate a certificate with another user's account, affecting the confidentiality and integrity of that account's encrypted mail and, where certificate-based login is enabled, potentially permitting unauthorized access to the account.
Title Kiteworks Email Protection Gateway Improper Access Control
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}


Subscriptions

Kiteworks Kiteworks Email Protection Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-10-01T13:37:07.938Z

Reserved: 2026-09-28T17:39:13.564Z

Link: CVE-2026-102149

cve-icon Vulnrichment

Updated: 2026-10-01T13:32:23.765Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T21:17:03.760

Modified: 2026-10-01T14:17:19.140

Link: CVE-2026-102149

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:30:08Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function