PT-2026-103548 · Kiteworks · Kiteworks Core
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kiteworks Core versions prior to 9.5.1
Description
Kiteworks Core fails to correctly validate a parameter within the password reset workflow. This allows an unauthenticated attacker who knows the email address of a user with a locally stored password to reset the account password without access to the reset link sent via email. This can lead to full account takeover, including accounts with administrative privileges.
Recommendations
Update Kiteworks Core to version 9.5.1.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kiteworks Core