External risk intelligence

Kiteworks Email Protection Gateway SSRF Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-102105

The affected product is an Email Protection Gateway, which is explicitly designed to sit at the network edge to inspect incoming traffic and process external communications, making it inherently internet-facing by design.

Server-Side Request Forgery

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in an email protection system could allow attackers to send crafted requests that expose internal information or trigger actions on your network. This issue arises when the system processes message content referencing external resources. The primary concern is to determine if your organization uses this specific technology and if it is exposed to external access.

  • Weakness allows external requests to internal systems.
  • Protects sensitive data and prevents system actions.
  • Confirm use and exposure to assess risk.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a specially crafted email to the Kiteworks Email Protection Gateway. When the gateway processes the email's content, which includes references to external resources, it can be tricked into making requests to internal or unintended network destinations. This could potentially reveal sensitive information or cause actions on internal systems.

  • Entry condition: Unauthenticated network access.
  • Trigger point: Rendering email content with external references.
  • Resulting risk: Sensitive information disclosure or internal system compromise.

Live Threat

Current exploitation, exposure, and threat context

A server-side request forgery vulnerability in Kiteworks Email Protection Gateway could allow an unauthenticated attacker to cause the gateway to send crafted requests to internal network resources. This could potentially expose sensitive internal information or trigger unintended actions on internal systems, depending on the services accessible from the gateway.

  • Internal network resources and services.
  • Crafted requests when rendering message content.
  • Disclosure of internal information.

Operational Fix

Recommended remediation, mitigation, and detection steps

To address this Server-Side Request Forgery (SSRF) vulnerability in the Kiteworks Email Protection Gateway, platform or infrastructure teams are likely responsible for managing the gateway's deployment. The immediate priority is to identify all instances of the affected technology, confirm their network reachability and business criticality, and pinpoint the accountable system owner. Subsequently, a risk-based remediation plan should be developed.

  • Platform or infrastructure teams own resolution.
  • Verify gateway exposure and critical systems.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Kiteworks Email Protection Gateway?

It is a specialized security appliance designed to sit at the edge of an organization's network. Its primary function is to inspect incoming email traffic, filter out malicious content, and manage secure communications before they reach the internal mail server.

What does CVE-2026-102105 mean by SSRF?

This vulnerability is classified as Server-Side Request Forgery (CWE-918). It means the gateway can be manipulated to make unauthorized network requests on behalf of an attacker, potentially reaching internal systems that are not meant to be accessed from the outside.

How is the SSRF triggered in this software?

The vulnerability occurs when the gateway attempts to render email message content that contains references to external resources. It does not trigger during standard operations that do not involve processing or fetching these embedded external references.

Is my organization at risk from this vulnerability?

Halo Surface Signal indicates this product is inherently internet-facing because it acts as a network-edge gateway. If you use this technology to process external email, your instance is likely reachable from the internet, increasing the potential for this flaw to be exploited.

When should I take action for this CVE?

You should prioritize identifying all deployed instances of the gateway immediately. Since platform or infrastructure teams typically manage this technology, they should verify the current version, confirm network placement, and develop a remediation plan to update the software.

References