VDB

CVE-2026-102101

CVE-2026-102101 PUBLISHED CVSS 8.1 HIGH

Reported by cisa-cg · Published September 30, 2026

Kiteworks Core before version 9.5.0 is vulnerable to Deserialization of Untrusted Data. A deserialization weakness in Kiteworks Core could, under certain conditions, allow crafted data to be deserialized unsafely, potentially resulting in remote code execution on the appliance. Exploitation depends on an attacker first being able to influence the affected data, so this issue is not exploitable on its own.

Risk Scores

CVSS 3.1
8.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersions
KiteworksCore0, 9.5.0
KiteworksCore0, 9.5.0, 0

Timeline

  • Sep 30, 2026 Coalition ESS Score
  • Sep 30, 2026 CVE Published
  • Oct 1, 2026 EPSS Score
  • Oct 2, 2026 EPSS Score
  • Oct 6, 2026 EPSS Score
  • Oct 7, 2026 CVE Updated

References

  • url vendor-advisory
  • url third-party-advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›