CRITICAL 9.8 CVE-2026-102115 Published 30 Sept 2026

Kiteworks Core Password Reset Authentication Bypass Vulnerability

Worried this affects your website?

Kiteworks Core contains a password reset authentication bypass vulnerability caused by incorrect validation of a parameter submitted to the password reset workflow.

An unauthenticated attacker who knew the email address of a user with a locally stored password could potentially:

  • Reset that account's password without access to the emailed reset link
  • Authenticate as that user
  • Do so even if the account holds administrative privileges

Reference: CVE-2026-102115 on NVD

← Back to Security News