External risk intelligence

Kiteworks Email Protection Gateway SSRF Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-102095

The affected product is an email protection gateway, which is designed to be public-facing to receive, process, and inspect external email traffic before it enters an internal network.

Server-Side Request Forgery

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a vulnerability in the Kiteworks Email Protection Gateway that could allow an unauthorized sender to trick the system into accessing internal resources. This capability might expose sensitive information or alter the state of internal services by making requests on behalf of the gateway. The primary concern is to determine if your organization uses this technology and if it is exposed to external email.

  • System could be tricked into accessing internal resources.
  • Email gateways are often public-facing, increasing risk.
  • Confirm use and exposure to understand potential impact.

Attack Path

How an attacker could exploit the issue

An attacker could send a specially crafted email to the Kiteworks Email Protection Gateway. The gateway would then make a server-side request to a URL within that email without sufficient restrictions on where it can connect. This could allow the attacker to access internal systems or cloud metadata, potentially revealing sensitive information or altering internal service states.

  • Entry requires unauthenticated network access.
  • Triggered by processing malicious email content.
  • Risk of sensitive data exposure and service manipulation.

Live Threat

Current exploitation, exposure, and threat context

A remote, unauthenticated sender could craft a malicious email message to trigger the Kiteworks Email Protection Gateway to make requests to internal services or cloud instance metadata endpoints. This could potentially expose sensitive internal data or alter the state of internal services.

  • Internal network information could be exposed.
  • Gateway fetches URLs from email content.
  • Internal service states may be affected.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Kiteworks Email Protection Gateway's Server-Side Request Forgery vulnerability requires a coordinated response. Typically, the platform or infrastructure team responsible for the gateway's deployment should lead the remediation effort. The first practical step is to identify all instances of the gateway, confirm their exposure and business criticality, and then engage the appropriate application or security teams to plan and execute mitigation strategies, potentially involving vendor coordination.

  • Platform or infrastructure teams own remediation.
  • Verify gateway exposure and business criticality.
  • Plan mitigation and coordinate with vendor.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Kiteworks Email Protection Gateway?

It is a specialized security appliance designed to sit at the edge of an organization's network. Its primary role is to intercept, inspect, and filter incoming email traffic from the internet before allowing it to pass into the internal mail environment, helping to protect internal systems from malicious content.

How does this SSRF vulnerability work in CVE-2026-102095?

This is a Server-Side Request Forgery (CWE-918) flaw. It occurs because the gateway processes URLs found within emails without proper validation. An attacker can supply a malicious URL, forcing the gateway to act as a proxy and make unauthorized requests to internal resources or cloud metadata services on their behalf.

Does a legitimate email trigger this vulnerability?

No. The gateway only becomes a tool for an attacker when it processes a specially crafted message designed to exploit its URL-fetching behavior. Standard, non-malicious emails that do not contain such targeted requests will not cause the gateway to interact with internal or unintended endpoints.

Why should I care about this vulnerability?

Halo Surface Signal indicates that because this product acts as an email gateway, it is inherently public-facing to receive external traffic. This position makes it a high-value entry point, as successful exploitation could allow an unauthorized remote sender to reach protected internal network services that are otherwise not exposed to the internet.

How do I begin responding to this CVE?

Start by identifying all instances of the Kiteworks Email Protection Gateway running in your environment. Confirm the current version to see if it falls below 9.5.0, evaluate the business criticality of those specific appliances, and coordinate with your infrastructure or platform teams to plan and execute the necessary updates or mitigation strategies.

References