OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102127

HIGH · CVSS 7 EPSS 0.19% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The XML parser in Kiteworks Email Protection Gateway is vulnerable due to insufficient restrictions on external entity references, allowing remote, unauthenticated attackers to exploit this weakness. If a specific message-processing feature is enabled, attackers can craft messages that may expose sensitive files, including cryptographic keys and credentials, to an external destination. Organizations using this gateway, particularly those with the optional feature activated, should prioritize remediation to mitigate the risk of data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102127
Severity
HIGH
CVSS
7
EPSS
0.19%

Original NVD Description

An XML parser used by Kiteworks Email Protection Gateway did not restrict external entity references. Where an optional, non-default message-processing feature is enabled, a remote and unauthenticated sender could potentially use a crafted message to read files accessible to the gateway service account, including cryptographic key material and credentials, and have them sent to a destination they control.