EUVD Vulnerability Catalog

EUVD-2026-90304

Severity: CRITICAL Base Score: 9.8 CVSS Version: 3.1

Vulnerability Description

Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who knew the email address of a user with a locally stored password could potentially reset that account's password without access to the emailed reset link and then authenticate as that user, including where the account holds administrative privileges.

CVSS Vector Analysis

Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

▪ Attack Vector (AV): Network
▪ Attack Complexity (AC): Low
▪ Privileges Required (PR): None
▪ User Interaction (UI): None
▪ Scope (S): Unchanged
▪ Confidentiality Impact (C): High
▪ Integrity Impact (I): High
▪ Availability Impact (A): High

Affected Vendors & Systems

Vendor Kiteworks

References & Advisory Links

Metadata Profile

Database Authority

European Union Agency for Cybersecurity (ENISA) EUVD

Assigner

cisa-cg

EPSS Probability

0

Known Aliases
CVE-2026-102115
Published On

2026-09-30

Last Updated

2026-09-30