CVE-2026-102135
Received Received - Intake

Kiteworks Email Protection Gateway Code Execution via Deserialization

Vulnerability report for CVE-2026-102135, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Description

On a Kiteworks Email Protection Gateway cluster with database replication enabled, a party trusted by the cluster could submit a crafted serialized object that was deserialized without sufficient validation, potentially allowing code execution as the gateway service account. Replication is disabled by default, and exploitation requires control of a trusted cluster peer or administrative access to the appliance.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a Kiteworks Email Protection Gateway cluster with database replication enabled. A trusted party could send a specially crafted serialized object that gets deserialized without proper validation, potentially leading to code execution as the gateway service account. Replication is not enabled by default, and exploiting this requires control of a trusted cluster peer or administrative access to the appliance.

Detection Guidance

Detection requires checking for signs of unauthorized code execution or unusual network activity from the gateway service account. Monitor logs for deserialization errors or unexpected processes. Verify if database replication is enabled on the Kiteworks Email Protection Gateway cluster.

Impact Analysis

If exploited, this vulnerability could allow an attacker to execute arbitrary code on the gateway service account, potentially leading to unauthorized access, data breaches, or further compromise of the system. The impact depends on the privileges of the gateway service account and the sensitivity of data processed by the appliance.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Organizations using affected Kiteworks systems may face legal penalties, reputational damage, and increased scrutiny from regulatory bodies.

Mitigation Strategies

Disable database replication if enabled, as it is not enabled by default. Ensure only trusted parties have access to cluster peers or administrative controls. Apply patches or updates from the vendor if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102135. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart