CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-102115: kiteworks before 9.5.0 (exclusive); +1 more affected products

CVE-2026-102115. CVSS 3.1 base score 9.8 (CRITICAL, Source advisory). EPSS 0.00334 (percentile 0.24635), scored 2026-10-06.

Affected technology

kiteworks · before 9.5.0 (exclusive)
accellion

Core · 0 to before 9.5.0
Kiteworks

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

Knew the email address of a user with a locally stored password could potentially reset that account's password without access to the emailed reset link and then authenticate as that user, including where the account holds administrative privileges. Source advisory’s CVSS 3.1 assessment (base score 9.8/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-640
CCR priority
39.3 /100 (P4)
CVSS 3.1
9.8 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H · Source advisory
EPSS
0.00334 · percentile 0.24635 · 2026-10-06
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-102115.html