CVE-2026-102128
Received Received - Intake

Identity Verification Bypass in Kiteworks Email Protection Gateway

Vulnerability report for CVE-2026-102128, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Description

An identity-verification weakness in Kiteworks Email Protection Gateway allowed the gateway to act on the Kiteworks platform on behalf of a user it had not authenticated, and to provision a platform account for an identity it did not already know. A remote, unauthenticated sender could potentially exploit this to obtain control of a platform account.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
kiteworks email_protection_gateway *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an identity-verification weakness in Kiteworks Email Protection Gateway. It allows the gateway to act on the Kiteworks platform on behalf of an unauthenticated user and create platform accounts for unknown identities. A remote attacker could exploit this to gain control of a platform account without proper authentication.

Impact Analysis

If exploited, this vulnerability could allow an attacker to take control of a platform account, potentially accessing sensitive data or performing unauthorized actions. It undermines user authentication and could lead to data breaches or unauthorized access to protected resources.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating compliance requirements under GDPR and HIPAA. It undermines data protection controls and may result in regulatory penalties due to insufficient authentication and access controls.

Mitigation Strategies

Apply the latest security patches or updates provided by Kiteworks for the Email Protection Gateway to address the identity-verification weakness. Review and restrict unauthenticated access to the gateway and monitor for suspicious account provisioning activities.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102128. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart