CVE-2026-102128: Accellion Kiteworks
High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.
An identity-verification weakness in Kiteworks Email Protection Gateway allowed the gateway to act on the Kiteworks platform on behalf of a user it had not authenticated, and to provision a platform account for an identity it did not already know. A remote, unauthenticated sender could potentially exploit this to obtain control of a platform account.
Affected products
- Accellion Kiteworks: before 9.5.1 (fixed in 9.5.1)
Published 2026-09-30. Last modified 2026-10-08.