CRITICAL 9.8 NVD

CVE-2026-102115

Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who knew the email address of a user

Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who knew the email address of a user with a locally stored password could potentially reset that account's password without access to the emailed reset link and then authenticate as that user, including where the account holds administrative privileges.

References

Published: 2026-09-30 · Source: NVD · Feed updated: 2026-10-01
This critical severity vulnerability with a CVSS score of 9.8 was published on 2026-09-30 via NVD.

Risk Timeline

CVE Disclosed2026-09-30 · 0 days ago

Remediation Resources

vulnfeed aggregates 9519 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.