Kiteworks Email Protection Gateway vulnerabilities
22 known vulnerabilities affecting kiteworks/email_protection_gateway.
Total CVEs
22
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH11MEDIUM4
Vulnerabilities
Page 2 of 2
CVE-2026-102139P3MEDIUMCVSS 6.5fixed in 9.5.12026-09-30
CVE-2026-102139 [MEDIUM] CWE-639 CVE-2026-102139: An authorization check in the large file exchange feature of Kiteworks Email Protection Gateway did
An authorization check in the large file exchange feature of Kiteworks Email Protection Gateway did not correctly establish that the requesting user was a party to the package being requested. An authenticated user of that optional feature could read the subject, message body, and attachments of packages they neither sent nor received.
nvd
CVE-2026-102144P4MEDIUMCVSS 5.3fixed in 9.5.12026-09-30
CVE-2026-102144 [MEDIUM] CWE-306 CVE-2026-102144: A resource exhaustion vulnerability in Kiteworks Email Protection Gateway allowed an unauthenticated
A resource exhaustion vulnerability in Kiteworks Email Protection Gateway allowed an unauthenticated remote attacker to repeatedly trigger a comparatively expensive server-side operation, causing a partial denial of service.
nvd
← Previous2 / 2