Description
On a Kiteworks Email Protection Gateway cluster with database replication enabled, a party trusted by the cluster could submit a crafted serialized object that was deserialized without sufficient validation, potentially allowing code execution as the gateway service account. Replication is disabled by default, and exploitation requires control of a trusted cluster peer or administrative access to the appliance.
Published: 2026-09-30
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

The vulnerability arises from a CWE-502 deserialization of untrusted data in the Kiteworks Email Protection Gateway. When database replication is enabled, a trusted peer can submit a crafted serialized object that the service processes without proper validation. This flaw can provide the attacker with full code execution privileges under the gateway service account, allowing manipulation, exfiltration, or further compromise of connected systems.

Affected Systems

It affects all deployments of the Kiteworks Email Protection Gateway that have database replication enabled. No specific version is disclosed, implying that any instance configured for replication is potentially vulnerable.

Risk and Exploitability

The CVSS score of 6.6 indicates moderate severity, reflecting that exploitation requires a trusted cluster relationship or administrative access. Replication is disabled by default, reducing the attack surface, yet an attacker who compromises a trusted peer or gains administrator rights can achieve complete control. The EPSS score is not available and the flaw is not listed in the CISA KEV catalog, but the possibility of remote code execution warrants rapid mitigation.

Generated by OpenCVE AI on September 30, 2026 at 22:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest patch or update from Kiteworks that fixes the deserialization flaw.
  • Disable database replication on the Email Protection Gateway if it is not required for your environment.
  • Limit the list of trusted cluster peers to only devices with a legitimate purpose and remove any that are unnecessary.
  • Configure firewall and network segmentation to restrict inbound connections from untrusted hosts, and monitor logs for suspicious deserialization activity.

Generated by OpenCVE AI on September 30, 2026 at 22:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Kiteworks
Kiteworks kiteworks Email Protection Gateway
Vendors & Products Kiteworks
Kiteworks kiteworks Email Protection Gateway

Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description On a Kiteworks Email Protection Gateway cluster with database replication enabled, a party trusted by the cluster could submit a crafted serialized object that was deserialized without sufficient validation, potentially allowing code execution as the gateway service account. Replication is disabled by default, and exploitation requires control of a trusted cluster peer or administrative access to the appliance.
Title Kiteworks Email Protection Gateway Deserialization of Untrusted Data
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Kiteworks Kiteworks Email Protection Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-10-01T13:37:06.765Z

Reserved: 2026-09-28T17:39:13.563Z

Link: CVE-2026-102135

cve-icon Vulnrichment

Updated: 2026-10-01T13:32:13.977Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T21:17:02.157

Modified: 2026-10-01T14:17:18.000

Link: CVE-2026-102135

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:30:08Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data