Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-102128

An identity-verification weakness in Kiteworks Email Protection Gateway allowed the gateway to act on the Kiteworks platform on behalf of a user it had not authenticated, and to provision a platform account for an identity it did not already know. A remote, unauthenticated sender could potentially exploit this to obtain control of a platform account.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 10.3%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2026-102128


Contact Us

Shodan ® - All rights reserved