OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-102149

CRITICAL · CVSS 9.4 EPSS 0.24% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The Kiteworks Email Protection Gateway is vulnerable due to inadequate restrictions on certificate assignment, allowing attackers to associate a certificate with another user's account. This flaw can compromise the confidentiality and integrity of encrypted emails and may enable unauthorized access if certificate-based login is utilized. Organizations using this gateway should prioritize remediation to protect sensitive communications and user accounts.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102149
Severity
CRITICAL
CVSS
9.4
EPSS
0.24%

Original NVD Description

Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could be assigned to. This could allow an attacker to associate a certificate with another user's account, affecting the confidentiality and integrity of that account's encrypted mail and, where certificate-based login is enabled, potentially permitting unauthorized access to the account.