OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102139

MEDIUM · CVSS 6.5 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The large file exchange feature in Kiteworks Email Protection Gateway has a vulnerability that allows authenticated users to access the contents of email packages—including subject, message body, and attachments—that they are not authorized to view. This could lead to unauthorized data exposure, impacting the confidentiality of sensitive information. Organizations using this feature should prioritize remediation to mitigate potential data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102139
Severity
MEDIUM
CVSS
6.5
EPSS
0.26%
Exchange

Original NVD Description

An authorization check in the large file exchange feature of Kiteworks Email Protection Gateway did not correctly establish that the requesting user was a party to the package being requested. An authenticated user of that optional feature could read the subject, message body, and attachments of packages they neither sent nor received.

Related CVEs

Other vulnerabilities affecting the same vendor(s)