CVE-2026-102115

Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who knew the email address of a user with a locally stored password could potentially reset that account's password without access to the emailed reset link and then authenticate as that user, including where the account holds administrative privileges.

  • Published Sep 30, 2026
  • CVSS 9.8 critical
  • 0.3% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2026-102115 at the National Vulnerability Database