External risk intelligence

Kiteworks Email Protection Gateway SSRF Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-102104

The product is an Email Protection Gateway, which is designed to sit at the network edge to inspect inbound traffic. By definition, such gateways are public-facing to receive and process external email traffic, making them an internet-exposed service by design.

Server-Side Request Forgery

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A server-side request forgery vulnerability has been identified in Kiteworks Email Protection Gateway, which could permit unauthenticated attackers to make the gateway send requests to internal network locations. This could potentially expose sensitive information or disrupt operations by exploiting the gateway's certificate status checking process.

  • Attackers can force the gateway to make unauthorized network requests.
  • It can expose internal information or disrupt services.
  • Confirm relevance and exposure of this gateway.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a specially crafted inbound email to the Kiteworks Email Protection Gateway. The gateway, while processing the email, would perform an online certificate status check. This check, if manipulated by the attacker's crafted request, could force the gateway to make requests to unintended internal or external network destinations. Depending on what services are accessible from the gateway, this could lead to the disclosure of sensitive information or disruption of the gateway's services.

  • No authentication required.
  • Triggered during certificate status check.
  • Disclose information or disrupt operations.

Live Threat

Current exploitation, exposure, and threat context

A server-side request forgery vulnerability in the Kiteworks Email Protection Gateway could allow an unauthenticated attacker to force the gateway to send requests to internal or unintended network destinations. This occurs during an online certificate status check for incoming messages, and depending on network configuration, could lead to the disclosure of sensitive internal information or disruption of the gateway's operations.

  • Gateway network access at risk.
  • Forged requests to unintended destinations.
  • Internal information disclosure or disruption.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Kiteworks Email Protection Gateway's SSRF vulnerability impacts organizations using this product for email security. The first practical step involves identifying all instances of the gateway, confirming their exposure and criticality, and then assigning ownership for remediation. Coordination between application owners, infrastructure teams, and potentially vendor management will be crucial for a risk-based response.

  • Application and Infrastructure teams own resolution.
  • Verify external reachability and critical business function.
  • Plan vendor coordination and risk reduction.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Kiteworks Email Protection Gateway?

It is a security appliance positioned at the network perimeter designed to inspect incoming email traffic for threats before it reaches your internal mail servers. By managing the flow of messages and verifying security protocols like digital certificates, it serves as a critical checkpoint for organizations aiming to block malicious communications.

What does Server-Side Request Forgery mean for CVE-2026-102104?

This vulnerability, classified as CWE-918, allows an attacker to manipulate the software into making requests to locations it should not access. Instead of the gateway communicating only with intended verification services, an attacker can trick it into reaching out to internal infrastructure or other unauthorized destinations.

How is the SSRF vulnerability triggered in this gateway?

The flaw is triggered specifically when the gateway performs an online certificate status check during the processing of an inbound email. It is not triggered by general email delivery or standard gateway operations; the attacker must supply a specifically crafted message that forces the gateway to initiate these unintended network requests.

Is my organization at risk if we use this product?

According to Halo Surface Signal, this product is designed to sit at the network edge to receive external email traffic, making it inherently internet-facing. Because it must be exposed to the internet to function, any instance of this gateway is potentially reachable by remote, unauthenticated attackers, increasing the relevance of this advisory.

Do I need to take immediate action if I run this software?

Yes, you should begin by locating all deployed instances of the gateway to confirm their current version and network exposure. Since versions before 9.5.0 are affected, coordinate with your infrastructure and security teams to prioritize these assets for updates and ensure your remediation plan aligns with the vendor's guidance.

References