CVE-2026-102104: Kiteworks Email Protection Gateway server-side request forgery
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway performs an online certificate status check for an inbound message. Depending on the services reachable from the gateway, this could disclose sensitive internal information or disrupt gateway operation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Kiteworks Email Protection Gatewayto a version that resolves this vulnerability.Fixed in 9.5.0
Event History
Frequently Asked Questions
Which deployments are affected?
Kiteworks Email Protection Gateway versions before 9.5.0 are affected. The vulnerable behavior occurs when the gateway performs an online certificate status check for an inbound message.
Does exploitation require authentication or user interaction?
No. The vulnerability can be exploited remotely by an unauthenticated attacker and does not require user interaction.
What can an attacker reach through the gateway?
An attacker may cause the gateway to send crafted requests to internal or otherwise unintended network destinations. The impact depends on which services are reachable from the gateway and may include disclosure of sensitive internal information or disruption of gateway operation.
What version resolves the issue?
Upgrade Kiteworks Email Protection Gateway to version 9.5.0 or later.