VDB

CVE-2026-102106

CVE-2026-102106 PUBLISHED CVSS 9.1 CRITICAL

Reported by cisa-cg · Published September 30, 2026

Improper authentication in a Kiteworks Email Protection Gateway administrative service. An administrative service in Kiteworks Email Protection Gateway did not consistently enforce administrator authentication, so the required password check could be bypassed. An attacker who referenced a valid administrator account could potentially create, modify, or delete internal users and managed domains and change their security-feature configuration without authenticating; deleting a managed domain also removes its user accounts and could lock administrators out of the gateway.

Risk Scores

CVSS 3.1
9.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Affected Products

VendorProductVersions
KiteworksEmail Protection Gateway0, 9.5.0
KiteworksEmail Protection Gateway0, 9.5.0, 0

Timeline

  • Sep 30, 2026 Coalition ESS Score
  • Sep 30, 2026 CVE Published
  • Oct 1, 2026 EPSS Score
  • Oct 2, 2026 EPSS Score
  • Oct 6, 2026 EPSS Score
  • Oct 8, 2026 CVE Updated

References

  • url vendor-advisory
  • url third-party-advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›