External risk intelligence

Kiteworks Email Protection Gateway SSRF Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-102103

Kiteworks Email Protection Gateway is an edge security appliance designed to be public-facing to inspect inbound email and attachments. As an internet-facing gateway that processes external traffic by design, its surface is inherently exposed to the public internet.

Server-Side Request Forgery

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Kiteworks Email Protection Gateway, allowing unauthenticated attackers to potentially send crafted requests from the gateway to internal or unintended network destinations. This could lead to the disclosure of sensitive internal information or disruption of gateway operations, depending on the network services accessible by the gateway.

  • Attackers can trick the gateway into sending requests.
  • This bypasses network controls for sensitive data.
  • Confirm if your email gateway is affected.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending a specially crafted inbound message to the Kiteworks Email Protection Gateway. This message will cause the gateway to retrieve a certificate revocation list, during which process it can be tricked into sending requests to internal network destinations. This can lead to the disclosure of sensitive information or disruption of the gateway's operations.

  • No authentication or user interaction needed.
  • Triggered during certificate revocation list retrieval.
  • Can expose internal information or disrupt services.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to trick the Kiteworks Email Protection Gateway into sending requests to internal network locations. This could expose sensitive internal data or disrupt the gateway's normal functioning, depending on what services are accessible from the gateway.

  • Internal network information could be exposed.
  • Crafted requests could be sent to unintended destinations.
  • Gateway operations may be disrupted.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Kiteworks Email Protection Gateway, an internet-facing appliance, is vulnerable to SSRF attacks. This could allow unauthenticated remote attackers to trigger crafted requests to internal systems, potentially disclosing sensitive information or disrupting operations. Ownership typically falls to the platform or infrastructure team managing the gateway, in coordination with security and vendor management. The first practical step is to identify all instances of the affected technology, assess their exposure and business criticality, and confirm the accountable owner to plan remediation based on risk.

  • Platform or infrastructure teams own.
  • Verify gateway reachability and criticality.
  • Plan remediation based on exposure.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Kiteworks Email Protection Gateway?

Kiteworks Email Protection Gateway is a security appliance positioned at the network edge to inspect incoming emails and attachments. Organizations use it to filter malicious content before it reaches internal mail servers. Because it processes external traffic by design, it serves as a critical checkpoint for communication security.

What does SSRF mean for CVE-2026-102103?

SSRF stands for Server-Side Request Forgery, identified here as CWE-918. It means an attacker can manipulate the gateway into acting as a proxy, forcing it to send network requests to destinations it can reach internally. Instead of communicating with expected servers, the gateway is tricked into interacting with unintended or sensitive internal resources.

How is this SSRF vulnerability triggered?

The vulnerability is triggered when the gateway attempts to retrieve a certificate revocation list (CRL) while processing an inbound message. An attacker sends a specially crafted message to initiate this process. Requests are not triggered by routine gateway operations that do not involve CRL retrieval.

Does my organization need to worry about this CVE?

Yes, if you run this software, you should prioritize this issue. According to Halo Surface Signal, this gateway is designed to be internet-facing to handle incoming email, which inherently exposes it to the public internet and makes it accessible to remote, unauthenticated attackers.

What should I do first to address CVE-2026-102103?

Your first step is to identify all instances of the Kiteworks Email Protection Gateway within your environment. Once identified, verify their versions to see if they are earlier than 9.5.0. Engage your infrastructure or security team to confirm ownership and evaluate the business impact of these gateways to plan your next steps.

References