External risk intelligence

Kiteworks Email Protection Gateway SSRF Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-102102

Kiteworks Email Protection Gateway is an internet-facing gateway product designed to handle inbound email traffic. As an edge device positioned to receive external messages, its primary function necessitates public network exposure by design, making it highly likely to be reachable from the internet.

Server-Side Request Forgery

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in the Kiteworks Email Protection Gateway that could allow unauthenticated attackers to make the system send requests to unintended network destinations. This could potentially expose sensitive internal information or disrupt operations, depending on the services accessible from the gateway.

  • Allows external requests to internal systems.
  • Impacts secure email flow and data.
  • Confirm if your email gateway is affected.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a specially crafted inbound message to a vulnerable Kiteworks Email Protection Gateway. The gateway, while attempting to retrieve an issuer certificate from the message, can be tricked into making requests to unintended network destinations. This could lead to the disclosure of internal information or service disruption.

  • Requires unauthenticated network access.
  • Triggered by retrieving a certificate from an inbound message.
  • Risk of information disclosure and service disruption.

Live Threat

Current exploitation, exposure, and threat context

A server-side request forgery (SSRF) vulnerability in Kiteworks Email Protection Gateway could allow an unauthenticated attacker to make the gateway send requests to internal or other unintended network locations. This could happen when the gateway retrieves an issuer certificate from an incoming message, potentially exposing sensitive internal information or disrupting the gateway's operation, depending on the services reachable by the gateway.

  • Internal network information disclosure.
  • Attacker crafts malicious inbound message.
  • Gateway disruption or internal data leak.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Kiteworks Email Protection Gateway is likely managed by a platform or infrastructure team responsible for email security appliances. The initial focus should be on identifying all instances of this gateway, assessing their network exposure and criticality to business operations, and then determining the accountable owner for remediation planning.

  • Identify and confirm gateway ownership.
  • Verify network exposure and impact.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Kiteworks Email Protection Gateway?

Kiteworks Email Protection Gateway is an enterprise software solution used to secure inbound email traffic. It acts as a gatekeeper, inspecting incoming messages and managing encryption and authentication protocols, such as certificate validation, to ensure safe communication before messages reach your internal email infrastructure.

What does CWE-918 mean for CVE-2026-102102?

CWE-918 refers to Server-Side Request Forgery (SSRF). In the context of this CVE, it means the gateway can be manipulated to send requests to destinations it was not intended to reach. Because the system trusts the gateway's position, it may inadvertently allow an attacker to probe internal networks or services that are typically hidden from the public internet.

How is this SSRF vulnerability triggered?

The flaw is triggered when the gateway attempts to retrieve an issuer certificate from a specially crafted inbound email message. It is not triggered by normal, legitimate email traffic that lacks malicious certificate retrieval instructions. The gateway must be processing a message that contains these specific, manipulated requests to be affected.

Is my instance of the gateway at risk?

According to Halo Surface Signal, this product is designed to be internet-facing to handle incoming email, making it highly likely that any instance is reachable from the public network. Because the gateway must be exposed to perform its function, any environment running a version before 9.5.0 should be treated as potentially reachable by an unauthenticated attacker.

What should I do if I run this software?

Start by identifying all instances of the Kiteworks Email Protection Gateway within your environment and confirm their current version numbers. If you are running a version earlier than 9.5.0, coordinate with your infrastructure or email security team to plan for an update. Prioritize these instances based on their connectivity to sensitive internal network segments.

References