Business Logic Flaw in Kiteworks Core File-Request Feature
CVE-2026-102107
4.6MEDIUM
What is CVE-2026-102107?
The Kiteworks Core product exhibits a business logic flaw within its file-request feature. This vulnerability enables an authenticated user to generate a request that falsely appears to come from another user. The underlying issue stems from the server's failure to verify the requester's authorization to represent the specified account. As a result, this flaw can be exploited to solicit files or sensitive information from a recipient, who may be led to trust the identity of the requester. For exploitation to succeed, the feature must be activated for the attacker's profile, and the targeted recipient must respond to the fraudulent request.
Affected Version(s)
Core 0 < 9.5.1
Core 9.5.1
References
CVSS V3.1
Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Supr4s, https://yeswehack.com/hunters/supr4s
Icare, https://yeswehack.com/hunters/icare
