---
id: CVE-2026-102101
title: >-
  Kiteworks Core before version 9.5.0 is vulnerable to Deserialization of
  Untrusted Data
summary: >-
  Kiteworks Core before version 9.5.0 is vulnerable to Deserialization of
  Untrusted Data. A deserialization weakness in Kiteworks Core could, under
  certain conditions, allow crafted data to be deserialized unsafely,
  potentially resulting i…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-502
vendor: Kiteworks
product: Core
affected:
  - Core < 9.5.0
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:16:56.880'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102101'
references:
  - url: >-
      https://github.com/kiteworks/security-advisories/security/advisories/GHSA-x5hx-fgrp-prvf
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T21:25:07.823Z'
---

## Overview

Kiteworks Core before version 9.5.0 is vulnerable to Deserialization of Untrusted Data. A deserialization weakness in Kiteworks Core could, under certain conditions, allow crafted data to be deserialized unsafely, potentially resulting in remote code execution on the appliance. Exploitation depends on an attacker first being able to influence the affected data, so this issue is not exploitable on its own.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
