CVE-2026-102115 – Kiteworks Core Authentication Bypass in the Password Reset Workflow

​CVE ID :CVE-2026-102115

Published : Sept. 30, 2026, 8:19 p.m. | 55 minutes ago

Description :Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who knew the email address of a user with a locally stored password could potentially reset that account’s password without access to the emailed reset link and then authenticate as that user, including where the account holds administrative privileges.

Severity: 9.8 | CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more… To Read More Visit Read More