Description
An authenticated administrator of Kiteworks Email Protection Gateway could submit a crafted serialized object to a cluster management interface that was deserialized without sufficient validation, potentially allowing arbitrary code execution in the context of the gateway service account. Exploitation requires an administrator account holding a specific queue-management privilege.
Published: 2026-09-30
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Apply Fix
AI Analysis

Impact

The vulnerability involves the deserialization of crafted serialized objects by the Kiteworks Email Protection Gateway without adequate validation. An attacker who is an authenticated administrator with queue‑management privileges can submit a malicious payload to the cluster management interface, potentially causing arbitrary code execution within the gateway service account. This weakness is classified as CWE‑502, which indicates unsafe deserialization leading to remote code execution, a severe impact on confidentiality, integrity, and availability of the protected email environment.

Affected Systems

Kiteworks Email Protection Gateway is affected. The vulnerability is limited to instances where an authenticated administrator holds the queue‑management privilege; no specific version range is disclosed, so all versions that do not yet implement proper validation may be vulnerable.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity. No EPSS score is available, but the requirement for administrative credentials suggests that exploitation is possible primarily in environments where privileged accounts are compromised or misconfigured. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to authenticate as an administrator with queue‑management rights, send a crafted serialized object to the cluster management endpoint, and achieve code execution in the context of the gateway service account. Given the high severity and the privileged context, the risk is considered significant for affected deployments.

Generated by OpenCVE AI on September 30, 2026 at 22:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Limit administrator accounts to the queue‑management privilege and enforce least‑privilege policies.
  • Patch or upgrade Kiteworks Email Protection Gateway to a version that validates serialized objects before deserialization.
  • Implement network segmentation to restrict access to the cluster management interface to trusted hosts only.

Generated by OpenCVE AI on September 30, 2026 at 22:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description An authenticated administrator of Kiteworks Email Protection Gateway could submit a crafted serialized object to a cluster management interface that was deserialized without sufficient validation, potentially allowing arbitrary code execution in the context of the gateway service account. Exploitation requires an administrator account holding a specific queue-management privilege.
Title Kiteworks Email Protection Gateway deserialization of untrusted data
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-09-30T20:24:07.786Z

Reserved: 2026-09-28T17:39:13.561Z

Link: CVE-2026-102108

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T21:16:57.737

Modified: 2026-09-30T21:16:57.737

Link: CVE-2026-102108

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T22:30:07Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data