Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 30 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authorization check in the large file exchange feature of Kiteworks Email Protection Gateway did not correctly establish that the requesting user was a party to the package being requested. An authenticated user of that optional feature could read the subject, message body, and attachments of packages they neither sent nor received. | |
| Title | Kiteworks Email Protection Gateway Incorrect Authorization | |
| Weaknesses | CWE-639 CWE-863 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2026-09-30T20:11:17.678Z
Reserved: 2026-09-28T17:39:13.564Z
Link: CVE-2026-102139
No data.
Status : Received
Published: 2026-09-30T21:17:02.663
Modified: 2026-09-30T21:17:02.663
Link: CVE-2026-102139
No data.
OpenCVE Enrichment
No data.