VYPR
advisoryPublished Sep 30, 2026· Updated Oct 2, 2026· 1 source

Kiteworks: 25 Coordinated Vulnerabilities Disclosed, Critical Flaws in Email Protection Gateway and Core

Key findings • 25 vulnerabilities disclosed for Kiteworks platform on September 30, 2026, spanning multiple components. • Critical vulnerabilities include SSRF, arbitrary password reset, and …

Key findings

  • 25 vulnerabilities disclosed for Kiteworks platform on September 30, 2026, spanning multiple components.
  • Critical vulnerabilities include SSRF, arbitrary password reset, and improper authentication in Email Protection Gateway.
  • Multiple CVEs involve arbitrary file writes and path traversal, potentially leading to OS command execution.
  • Patches are available, with specific versions noted for some fixes, emphasizing urgent updates.
  • The batch highlights systemic weaknesses requiring comprehensive security response from administrators.

On September 30, 2026, a significant batch of 25 vulnerabilities was disclosed for the Kiteworks platform, spanning multiple components including the Core, Email Protection Gateway, and Advanced Forms. These vulnerabilities, with CVSS scores ranging from medium to critical, were all published within minutes of each other, indicating a coordinated disclosure event. The sheer volume and severity of these flaws highlight potential systemic weaknesses within the Kiteworks ecosystem, necessitating urgent attention from administrators and security teams.

Several vulnerabilities center on improper authentication and authorization checks. CVE-2026-102150, a High severity flaw, reveals that a function in the Advanced Forms component was accessible without authentication, potentially allowing limited internal service operations. Similarly, CVE-2026-102149 (Critical, 9.4) and CVE-2026-102106 (Critical, 9.1) involve improper certificate assignment and bypassed administrator authentication in the Email Protection Gateway, respectively. A critical password reset vulnerability, CVE-2026-102115 (Critical, 9.8), could allow an unauthenticated attacker to reset a user's password without access to the reset link.

A notable theme across multiple CVEs is the potential for arbitrary file writes and path traversal, often leading to command execution. CVE-2026-102143 (High, 7.5) describes an unauthenticated attacker writing files to arbitrary locations via an administrative upload handler. CVE-2026-102142 (High, 7.2) details how an authenticated System Administrator could store a crafted template that executes OS commands. Furthermore, CVE-2026-102136 (Medium, 6.3) and CVE-2026-102099 (High, 7.2) also involve authenticated users writing files to unintended locations, potentially leading to command execution.

Server-Side Request Forgery (SSRF) is another critical vulnerability present in this batch, affecting the Kiteworks Email Protection Gateway. CVE-2026-102105, CVE-2026-102104, and CVE-2026-102024, all rated Critical with a 9.1 CVSS score, indicate that remote, unauthenticated attackers can induce the gateway to issue crafted requests to internal or unintended network destinations. This could expose sensitive internal resources and services.

Other vulnerabilities include privilege escalation through role assignment flaws (CVE-2026-102122), insecure handling of cluster management operations (CVE-2026-102141), and insufficient validation of administrative imports (CVE-2026-102140). The batch also includes flaws related to bypassing security controls on API requests (CVE-2026-102134) and issues within the document conversion sandbox (CVE-2026-102125).

The Kiteworks advisories indicate that patches are available for these vulnerabilities, with specific versions mentioned for some fixes. For instance, CVE-2026-102105, CVE-2026-102104, CVE-2026-102024, and CVE-2026-102099 are noted as affecting versions before 9.5.0, implying that version 9.5.0 and later contain fixes. Administrators are strongly advised to consult the official Kiteworks security advisories for detailed patching instructions and affected version information.

This coordinated disclosure of numerous high-severity vulnerabilities underscores the critical importance of maintaining up-to-date security configurations and applying patches promptly for the Kiteworks platform. The variety of attack vectors, from unauthenticated access to privilege escalation and SSRF, presents a complex threat landscape that requires a comprehensive security response. Users should prioritize addressing these flaws to mitigate the risk of potential compromise and ensure the integrity and confidentiality of their data.

The disclosed vulnerabilities include:

  • Improper Authentication & Authorization: Flaws allowing unauthenticated access to functions, improper certificate assignments, and bypassed administrator authentication.
  • Arbitrary File Write & Path Traversal: Multiple instances where attackers can write files to unintended locations, potentially leading to code execution.
  • Server-Side Request Forgery (SSRF): Critical vulnerabilities in the Email Protection Gateway allowing attackers to target internal network resources.
  • Privilege Escalation: Issues related to role assignments and the ability to gain higher privileges within the system.
  • Sandbox Escapes: Vulnerabilities allowing code within a sandbox to break out and gain higher privileges.

The affected components include Kiteworks Core, Email Protection Gateway, and Advanced Forms. The severity ranges from Medium to Critical, with several CVEs rated 9.0 or higher.

Kiteworks has released patches for these vulnerabilities. Specific versions are mentioned for some fixes, such as versions before 9.5.0 being vulnerable to SSRF and arbitrary file write issues. It is crucial for administrators to consult official Kiteworks advisories for detailed patching information and to update their systems accordingly.

This large batch of vulnerabilities highlights the need for continuous security vigilance and prompt patching for the Kiteworks platform. The diverse nature of the flaws, including SSRF and arbitrary file writes, necessitates a thorough review and update process to safeguard sensitive data and system integrity.

CVE-2026-102150, CVE-2026-102149, CVE-2026-102146, CVE-2026-102145, CVE-2026-102143, CVE-2026-102142, CVE-2026-102141, CVE-2026-102140, CVE-2026-102138, CVE-2026-102137, CVE-2026-102136, CVE-2026-102134, CVE-2026-102125, CVE-2026-102123, CVE-2026-102122, CVE-2026-102119, CVE-2026-102117, CVE-2026-102115, CVE-2026-102110, CVE-2026-102107, CVE-2026-102106, CVE-2026-102105, CVE-2026-102104, CVE-2026-102102, CVE-2026-102099

Synthesized by Vypr AI