VDB

CVE-2026-102115

CVE-2026-102115 PUBLISHED CVSS 9.8 CRITICAL

Reported by cisa-cg · Published September 30, 2026

Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who knew the email address of a user with a locally stored password could potentially reset that account's password without access to the emailed reset link and then authenticate as that user, including where the account holds administrative privileges.

Risk Scores

CVSS 3.1
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
KiteworksCore0, 9.5.0
KiteworksCore0, 9.5.0, 0

Timeline

  • Sep 30, 2026 Coalition ESS Score
  • Sep 30, 2026 CVE Published
  • Oct 1, 2026 EPSS Score
  • Oct 2, 2026 EPSS Score
  • Oct 6, 2026 EPSS Score
  • Oct 7, 2026 CVE Updated

References

  • url vendor-advisory
  • url third-party-advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›