CVE-2026-102108

HIGH Status: Received

CVSS Scores

CVSS v3.x Base Score
7.2
HIGH

Description

An authenticated administrator of Kiteworks Email Protection Gateway could submit a crafted serialized object to a cluster management interface that was deserialized without sufficient validation, potentially allowing arbitrary code execution in the context of the gateway service account. Exploitation requires an administrator account holding a specific queue-management privilege.

Published
September 30, 2026 9:16 PM
Last Modified
September 30, 2026 9:16 PM
Source
9119a7d8-5eab-497f-8521-727c672e3725

Weaknesses (CWE)

CWE-502

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.