CVE-2026-102106

CRITICAL Status: Received

CVSS Scores

CVSS v3.x Base Score
9.1
CRITICAL

Description

Improper authentication in a Kiteworks Email Protection Gateway administrative service. An administrative service in Kiteworks Email Protection Gateway did not consistently enforce administrator authentication, so the required password check could be bypassed. An attacker who referenced a valid administrator account could potentially create, modify, or delete internal users and managed domains and change their security-feature configuration without authenticating; deleting a managed domain also removes its user accounts and could lock administrators out of the gateway.

Published
September 30, 2026 9:16 PM
Last Modified
September 30, 2026 9:16 PM
Source
9119a7d8-5eab-497f-8521-727c672e3725

Weaknesses (CWE)

CWE-287

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.