CVE-2026-102108: Kiteworks Email Protection Gateway deserialization of untrusted data
An authenticated administrator of Kiteworks Email Protection Gateway could submit a crafted serialized object to a cluster management interface that was deserialized without sufficient validation, potentially allowing arbitrary code execution in the context of the gateway service account. Exploitation requires an administrator account holding a specific queue-management privilege.
Affected Software
Event History
Frequently Asked Questions
Which accounts can exploit this issue?
Exploitation requires an authenticated administrator account that has the specific queue-management privilege. Administrators without that privilege are not described as able to exploit the issue.
What access does an attacker need to trigger the vulnerability?
The attacker must be able to submit a crafted serialized object to the cluster management interface. The issue is exploitable remotely, but it is not unauthenticated because administrator credentials and the required privilege are needed.
What is the likely impact if exploitation succeeds?
A successful exploit could allow arbitrary code execution in the context of the gateway service account. The reported impact includes high confidentiality, integrity, and availability effects.