CRITICAL
9.8 CVE-2026-102115 Published 30 Sept 2026
Kiteworks Core Password Reset Authentication Bypass Vulnerability
Worried this affects your website?
Kiteworks Core contains a password reset authentication bypass vulnerability caused by incorrect validation of a parameter submitted to the password reset workflow.
An unauthenticated attacker who knew the email address of a user with a locally stored password could potentially:
- Reset that account's password without access to the emailed reset link
- Authenticate as that user
- Do so even if the account holds administrative privileges
Reference: CVE-2026-102115 on NVD
← Back to Security News