Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 30 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An identity-verification weakness in Kiteworks Email Protection Gateway allowed the gateway to act on the Kiteworks platform on behalf of a user it had not authenticated, and to provision a platform account for an identity it did not already know. A remote, unauthenticated sender could potentially exploit this to obtain control of a platform account. | |
| Title | Kiteworks Email Protection Gateway Improper Authentication | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2026-09-30T20:14:40.084Z
Reserved: 2026-09-28T17:39:13.563Z
Link: CVE-2026-102128
No data.
Status : Received
Published: 2026-09-30T21:17:01.270
Modified: 2026-09-30T21:17:01.270
Link: CVE-2026-102128
No data.
OpenCVE Enrichment
Updated: 2026-09-30T22:15:14Z
-
CWE-287
Improper Authentication