Deserialization Flaw in Kiteworks Email Protection Gateway
CVE-2026-102135

6.6MEDIUM

Key Information:

Vendor

Kiteworks

Vendor
CVE Published:
30 September 2026

What is CVE-2026-102135?

A deserialization vulnerability exists in the Kiteworks Email Protection Gateway when database replication is enabled. This flaw allows a malicious actor with access to a trusted peer in the cluster to submit a specially crafted serialized object, which the system deserializes without adequate validation. This could lead to arbitrary code execution under the privileges of the gateway service account. Effective mitigation requires careful management of cluster peer controls, as replication is disabled by default, emphasizing the need for stringent administrative access management.

Affected Version(s)

Email Protection Gateway 0 < 9.5.1

Email Protection Gateway 9.5.1

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Icare, https://yeswehack.com/hunters/icare
wlayzz, https://yeswehack.com/hunters/wlayzz
truff, https://yeswehack.com/hunters/truff
.