Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kiteworks
Kiteworks kiteworks Email Protection Gateway |
|
| Vendors & Products |
Kiteworks
Kiteworks kiteworks Email Protection Gateway |
Thu, 01 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 30 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | On a Kiteworks Email Protection Gateway cluster with database replication enabled, a party trusted by the cluster could submit a crafted serialized object that was deserialized without sufficient validation, potentially allowing code execution as the gateway service account. Replication is disabled by default, and exploitation requires control of a trusted cluster peer or administrative access to the appliance. | |
| Title | Kiteworks Email Protection Gateway Deserialization of Untrusted Data | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2026-10-01T13:37:06.765Z
Reserved: 2026-09-28T17:39:13.563Z
Link: CVE-2026-102135
Updated: 2026-10-01T13:32:13.977Z
Status : Awaiting Analysis
Published: 2026-09-30T21:17:02.157
Modified: 2026-10-01T14:17:18.000
Link: CVE-2026-102135
No data.
OpenCVE Enrichment
Updated: 2026-10-01T15:30:08Z
-
CWE-502
Deserialization of Untrusted Data