Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-102094

Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Unsafe Reflection and does not sufficiently restrict the code that the mail-processing pipeline could load from an imported rule configuration. An authenticated administrator with mail-rule configuration privileges could cause the gateway to load and execute code beyond the approved set of mail-processing components, potentially in the context of the mail-gateway service account.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 39.1%
CVSS Severity
CVSS v3 Score 7.2
Products affected by CVE-2026-102094


Contact Us

Shodan ® - All rights reserved