Deserialization Vulnerability in Kiteworks Core by Kiteworks
CVE-2026-102101

8.1HIGH

Key Information:

Vendor

Kiteworks

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-102101?

Kiteworks Core prior to version 9.5.0 has a security vulnerability related to deserialization of untrusted data. This flaw could allow an attacker to manipulate the deserialized data, potentially resulting in remote code execution on the affected appliance. However, successful exploitation requires the attacker to influence the vulnerable data, as this issue is not inherently exploitable on its own.

Affected Version(s)

Core 0 < 9.5.0

Core 9.5.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Icare, https://yeswehack.com/hunters/icare
Supr4s, https://yeswehack.com/hunters/Supr4s
wlayzz, https://yeswehack.com/hunters/wlayzz
truff, https://yeswehack.com/hunters/truff
.