Business Logic Flaw in Kiteworks Core File-Request Feature
CVE-2026-102107

4.6MEDIUM

Key Information:

Vendor

Kiteworks

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-102107?

The Kiteworks Core product exhibits a business logic flaw within its file-request feature. This vulnerability enables an authenticated user to generate a request that falsely appears to come from another user. The underlying issue stems from the server's failure to verify the requester's authorization to represent the specified account. As a result, this flaw can be exploited to solicit files or sensitive information from a recipient, who may be led to trust the identity of the requester. For exploitation to succeed, the feature must be activated for the attacker's profile, and the targeted recipient must respond to the fraudulent request.

Affected Version(s)

Core 0 < 9.5.1

Core 9.5.1

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Supr4s, https://yeswehack.com/hunters/supr4s
Icare, https://yeswehack.com/hunters/icare
.