Description
Kiteworks Core before version 9.5.0 is vulnerable to Deserialization of Untrusted Data. A deserialization weakness in Kiteworks Core could, under certain conditions, allow crafted data to be deserialized unsafely, potentially resulting in remote code execution on the appliance. Exploitation depends on an attacker first being able to influence the affected data, so this issue is not exploitable on its own.
Published: 2026-09-30
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

A deserialization weakness (CWE‑502) in Kiteworks Core allows crafted data to be unsafely deserialized, potentially leading to remote code execution on the appliance. The flaw resides in the processing of untrusted serialized payloads, giving an attacker the possibility to execute arbitrary code if the payload is successfully processed. No generic bypass is available and the vulnerability remains conditional on attacker influence over the data fed to the deserialization routine.

Affected Systems

The vulnerability affects Kiteworks Core installations before version 9.5.0. Service descriptions are limited to the Core product; no specific sub‑components list is provided.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity risk; however, the EPSS score is unavailable and the vulnerability is not listed in CISA KEV, suggesting a lower likelihood of immediate exploitation. The attack vector is likely remote, requiring the attacker to deliver crafted serialized data to the affected application. Since exploitation depends on an attacker controlling the input data, the vulnerability is not automatically exploitable on its own and would require prior compromise or a separate vector to influence the payload.

Generated by OpenCVE AI on September 30, 2026 at 22:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Kiteworks Core to version 9.5.0 or later to eliminate the deserialization flaw.
  • If an upgrade cannot be performed immediately, isolate the appliance from untrusted networks, restrict any endpoints that accept serialized data and ensure that only authenticated and authorized services can provide such data.
  • Implement logging and monitoring on the deserialization entry points to detect suspicious activity and review logs regularly for attempts to inject crafted payloads.
  • Check the vendor's website or security advisories for the latest patch or update.

Generated by OpenCVE AI on September 30, 2026 at 22:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 06:00:00 +0000

Type Values Removed Values Added
First Time appeared Kiteworks
Kiteworks core
Vendors & Products Kiteworks
Kiteworks core

Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description Kiteworks Core before version 9.5.0 is vulnerable to Deserialization of Untrusted Data. A deserialization weakness in Kiteworks Core could, under certain conditions, allow crafted data to be deserialized unsafely, potentially resulting in remote code execution on the appliance. Exploitation depends on an attacker first being able to influence the affected data, so this issue is not exploitable on its own.
Title Kiteworks Core deserialization of untrusted data
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-09-30T20:11:24.441Z

Reserved: 2026-09-28T17:39:13.561Z

Link: CVE-2026-102101

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T21:16:56.880

Modified: 2026-10-01T02:17:43.350

Link: CVE-2026-102101

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T05:45:16Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data