Deserialization Flaw in Kiteworks Email Protection Gateway
CVE-2026-102135
6.6MEDIUM
What is CVE-2026-102135?
A deserialization vulnerability exists in the Kiteworks Email Protection Gateway when database replication is enabled. This flaw allows a malicious actor with access to a trusted peer in the cluster to submit a specially crafted serialized object, which the system deserializes without adequate validation. This could lead to arbitrary code execution under the privileges of the gateway service account. Effective mitigation requires careful management of cluster peer controls, as replication is disabled by default, emphasizing the need for stringent administrative access management.
Affected Version(s)
Email Protection Gateway 0 < 9.5.1
Email Protection Gateway 9.5.1
References
CVSS V3.1
Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Icare, https://yeswehack.com/hunters/icare
wlayzz, https://yeswehack.com/hunters/wlayzz
truff, https://yeswehack.com/hunters/truff
