CVE-2026-102139
An authorization check in the large file exchange feature of Kiteworks Email Protection Gateway did not correctly establish that the requesting user was a party to the package being requested. An authenticated user of that optional feature could read the subject, message body, and attachments of packages they neither sent nor received.
- Published Sep 30, 2026
- CVSS 6.5 medium
- 0.3% chance of exploitation in the next 30 days (EPSS)