CVE-2026-102127: Kiteworks Email Protection Gateway Improper Restriction of XML External Entity Reference
An XML parser used by Kiteworks Email Protection Gateway did not restrict external entity references. Where an optional, non-default message-processing feature is enabled, a remote and unauthenticated sender could potentially use a crafted message to read files accessible to the gateway service account, including cryptographic key material and credentials, and have them sent to a destination they control.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Only deployments with the affected optional, non-default message-processing feature enabled are described as exposed. The issue affects the XML parser used by Kiteworks Email Protection Gateway in that configuration.
Does exploitation require an authenticated account or user interaction?
No. The described attack can be performed by a remote, unauthenticated sender using a crafted message, and it does not require user interaction.
What could an attacker obtain through successful exploitation?
An attacker could read files accessible to the gateway service account and send their contents to an attacker-controlled destination. The affected files may include cryptographic key material and credentials.