Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kiteworks
Kiteworks kiteworks Email Protection Gateway |
|
| Vendors & Products |
Kiteworks
Kiteworks kiteworks Email Protection Gateway |
Thu, 01 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 30 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An identity-verification weakness in Kiteworks Email Protection Gateway allowed the gateway to act on the Kiteworks platform on behalf of a user it had not authenticated, and to provision a platform account for an identity it did not already know. A remote, unauthenticated sender could potentially exploit this to obtain control of a platform account. | |
| Title | Kiteworks Email Protection Gateway Improper Authentication | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2026-10-01T13:37:05.460Z
Reserved: 2026-09-28T17:39:13.563Z
Link: CVE-2026-102128
Updated: 2026-10-01T13:32:03.366Z
Status : Awaiting Analysis
Published: 2026-09-30T21:17:01.270
Modified: 2026-10-01T14:17:17.143
Link: CVE-2026-102128
No data.
OpenCVE Enrichment
Updated: 2026-10-01T15:30:08Z
-
CWE-287
Improper Authentication