Deserialization Vulnerability in Kiteworks Core by Kiteworks
CVE-2026-102101
8.1HIGH
What is CVE-2026-102101?
Kiteworks Core prior to version 9.5.0 has a security vulnerability related to deserialization of untrusted data. This flaw could allow an attacker to manipulate the deserialized data, potentially resulting in remote code execution on the affected appliance. However, successful exploitation requires the attacker to influence the vulnerable data, as this issue is not inherently exploitable on its own.
Affected Version(s)
Core 0 < 9.5.0
Core 9.5.0
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Icare, https://yeswehack.com/hunters/icare
Supr4s, https://yeswehack.com/hunters/Supr4s
wlayzz, https://yeswehack.com/hunters/wlayzz
truff, https://yeswehack.com/hunters/truff
