CVE-2026-102115
Received Received - Intake

Authentication Bypass in Kiteworks Core via Password Reset

Vulnerability report for CVE-2026-102115, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Description

Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who knew the email address of a user with a locally stored password could potentially reset that account's password without access to the emailed reset link and then authenticate as that user, including where the account holds administrative privileges.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
kiteworks core *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-640 The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Kiteworks Core had a flaw in the password reset process where it did not properly validate a user-provided parameter. This allowed an unauthenticated attacker who knew the email address of a user with a locally stored password to reset that account's password without needing access to the emailed reset link. The attacker could then log in as that user, including if the account had administrative privileges.

Detection Guidance

This vulnerability involves improper validation in the password reset workflow of Kiteworks Core. Detection requires checking for unauthorized password resets without email confirmation. Review server logs for reset requests without corresponding email triggers or unusual password change activities. No specific commands are provided in the context.

Impact Analysis

If you are a user of Kiteworks Core with a locally stored password, an attacker could take over your account by resetting your password without needing access to your email. This could lead to unauthorized access to your data, potential data theft, or misuse of your account privileges if you are an administrator.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Organizations using Kiteworks Core may face legal and regulatory penalties if this flaw results in data breaches or unauthorized access to protected information.

Mitigation Strategies

Apply the latest security patch from Kiteworks to fix the password reset validation flaw. Ensure all user accounts, especially administrative ones, have strong passwords and enable multi-factor authentication if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102115. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart