CVE-2026-102115 PUBLISHED

Kiteworks Core Authentication Bypass in the Password Reset Workflow

Assigner: cisa-cg
Reserved: 28.09.2026 Published: 30.09.2026 Updated: 01.10.2026

Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who knew the email address of a user with a locally stored password could potentially reset that account's password without access to the emailed reset link and then authenticate as that user, including where the account holds administrative privileges.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor Kiteworks
Product Core
Versions Default: unknown
  • affected from 0 to 9.5.0 (excl.)
  • Version 9.5.0 is unaffected

Credits

  • Icare, https://yeswehack.com/hunters/icare
  • Supr4s, https://yeswehack.com/hunters/Supr4s
  • wlayzz, https://yeswehack.com/hunters/wlayzz
  • truff, https://yeswehack.com/hunters/truff

References

Problem Types

  • CWE-640 Weak Password Recovery Mechanism for Forgotten Password CWE