OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102108

HIGH · CVSS 7.2 EPSS 0.47% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

An authenticated administrator of Kiteworks Email Protection Gateway is vulnerable due to improper validation of serialized objects submitted to the cluster management interface, which could lead to arbitrary code execution within the gateway service account. This high-severity vulnerability necessitates immediate attention from organizations using Kiteworks Email Protection Gateway, particularly those with administrators holding queue-management privileges, to mitigate potential exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit arbitrary code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102108
Severity
HIGH
CVSS
7.2
EPSS
0.47%

Original NVD Description

An authenticated administrator of Kiteworks Email Protection Gateway could submit a crafted serialized object to a cluster management interface that was deserialized without sufficient validation, potentially allowing arbitrary code execution in the context of the gateway service account. Exploitation requires an administrator account holding a specific queue-management privilege.