External risk intelligence

Kiteworks Core Password Reset Vulnerability Allows Account Takeover

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-102115

Kiteworks is designed as an internet-facing file sharing and managed file transfer gateway. The password reset workflow is a public-facing service function, making the vulnerability directly reachable over the internet in standard deployments of this appliance.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Kiteworks Core that allows an unauthenticated attacker to reset user passwords, including administrative accounts, by exploiting an improper parameter validation in the password reset workflow. This could potentially lead to unauthorized access and control of sensitive systems.

  • Attackers can reset passwords without email verification.
  • Sensitive accounts could be compromised by external attackers.
  • Confirm relevance and exposure to prevent unauthorized access.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker who knows a user's email address can reset that user's password without needing access to the reset email. This allows the attacker to log in as the user, potentially gaining administrative access.

  • Unauthenticated network access required.
  • Password reset parameter not validated.
  • Unauthorized account access and control.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, an unauthenticated attacker who knows a user's email address could potentially reset that account's password and authenticate as that user, even if the account has administrative privileges.

  • User accounts and their privileges.
  • Password reset workflow allows unauthorized access.
  • Compromised accounts could lead to unauthorized actions.

Operational Fix

Recommended remediation, mitigation, and detection steps

Determining ownership requires identifying where Kiteworks Core is deployed and confirming its business criticality, which then helps pinpoint the accountable team, likely a combination of application owners, infrastructure, or platform teams. The immediate priority is to confirm the presence and exposure of Kiteworks Core instances, assess their reachability and impact, and then proceed with a risk-based remediation plan, potentially involving vendor coordination or temporary mitigations if direct remediation is not immediately feasible.

  • Own the issue: Application or infrastructure owners.
  • Verify first: Kiteworks Core deployment and exposure.
  • Action: Plan and coordinate remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Kiteworks Core?

Kiteworks Core is a software platform designed for secure file sharing and managed file transfers. It acts as a gateway for organizations to move sensitive data, providing tools to control, protect, and track file access both internally and with external partners.

What is the vulnerability in CVE-2026-102115?

This vulnerability is classified as CWE-640, or 'Weak Password Recovery Mechanism.' It occurs because the software fails to properly validate inputs during the password reset process. This flaw allows someone to bypass security checks and change a user's password without legitimate verification.

How does an attacker trigger this vulnerability?

An attacker needs the email address of a target user to exploit this flaw. By sending a specially crafted request to the password reset workflow, they can trigger a password change without having access to the official reset email. It is important to note that this attack does not rely on guessing passwords or stealing reset tokens.

Why is this CVE considered relevant to my infrastructure?

Halo Surface Signal notes that Kiteworks is built to be internet-facing, meaning its services are typically reachable from the public web. Since the password reset workflow is a public-facing function, any Kiteworks instance exposed to the internet is a potential target for unauthorized access.

How should I respond to this threat?

Start by identifying all deployed instances of Kiteworks Core within your environment. Once located, coordinate with your infrastructure and application teams to assess their reachability. Prioritize verifying your deployment status and work toward applying the necessary vendor updates to secure the password reset workflow.

References