VDB
CVE-2026-102101
CVE-2026-102101
PUBLISHED
CVSS 8.1 HIGH
Reported by cisa-cg · Published September 30, 2026
Kiteworks Core before version 9.5.0 is vulnerable to Deserialization of Untrusted Data. A deserialization weakness in Kiteworks Core could, under certain conditions, allow crafted data to be deserialized unsafely, potentially resulting in remote code execution on the appliance. Exploitation depends on an attacker first being able to influence the affected data, so this issue is not exploitable on its own.
Risk Scores
CVSS 3.1
8.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kiteworks | Core | 0, 9.5.0 |
| Kiteworks | Core | 0, 9.5.0, 0 |
Timeline
- Sep 30, 2026 Coalition ESS Score
- Sep 30, 2026 CVE Published
- Oct 1, 2026 EPSS Score
- Oct 2, 2026 EPSS Score
- Oct 6, 2026 EPSS Score
- Oct 7, 2026 CVE Updated