VDB
CVE-2026-102139
CVE-2026-102139
PUBLISHED
CVSS 6.5 MEDIUM
Reported by cisa-cg · Published September 30, 2026
An authorization check in the large file exchange feature of Kiteworks Email Protection Gateway did not correctly establish that the requesting user was a party to the package being requested. An authenticated user of that optional feature could read the subject, message body, and attachments of packages they neither sent nor received.
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kiteworks | Email Protection Gateway | 0, 9.5.1 |
| Kiteworks | Email Protection Gateway | 0, 9.5.1, 0 |
Timeline
- Sep 30, 2026 CVE Published
- Oct 1, 2026 EPSS Score
- Oct 2, 2026 EPSS Score
- Oct 7, 2026 EPSS Score
- Oct 7, 2026 CVE Updated