OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102128

HIGH · CVSS 7.5 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The Kiteworks Email Protection Gateway has an identity-verification vulnerability that allows an unauthenticated remote sender to impersonate a legitimate user and provision a new account on the Kiteworks platform. This could lead to unauthorized access and control over platform accounts, posing a significant risk to user data and system integrity. Organizations using Kiteworks should prioritize addressing this vulnerability to safeguard their email communications and user accounts.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102128
Severity
HIGH
CVSS
7.5
EPSS
0.21%

Original NVD Description

An identity-verification weakness in Kiteworks Email Protection Gateway allowed the gateway to act on the Kiteworks platform on behalf of a user it had not authenticated, and to provision a platform account for an identity it did not already know. A remote, unauthenticated sender could potentially exploit this to obtain control of a platform account.