TL;DR
Kiteworks disclosed 78 security flaws across its Core platform, Email Protection Gateway, and forms products. Nine of these Kiteworks vulnerabilities rate Critical, led by a 9.8 password reset flaw that can hand over admin accounts. Version 9.5.1 fixes them all, and no source reports in-the-wild attacks yet.
- Total: 78 CVEs
- Severity: 9 Critical · 35 High · 29 Medium · 5 Low
- Actively exploited: None confirmed
- Highest severity: 9.8 (Critical · CVSSv3) — CVE-2026-102115
- Action: Apply the latest security updates now
Track every CVE that hits your stack the moment it's exploited.
Get free email alertsNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-102115 | 9.8 | CWE-640 | 9.5.0 | Not exploited |
| CVE-2026-102149 | 9.4 | CWE-306 | 9.5.1 | Not exploited |
| CVE-2026-102147 | 9.3 | CWE-79 | 9.5.1 | Not exploited |
| CVE-2026-102106 | 9.1 | CWE-287 | 9.5.0 | Not exploited |
| CVE-2026-102105 | 9.1 | CWE-918 | 9.5.0 | Not exploited |
| CVE-2026-102104 | 9.1 | CWE-918 | 9.5.0 | Not exploited |
| CVE-2026-102103 | 9.1 | CWE-918 | 9.5.0 | Not exploited |
| CVE-2026-102102 | 9.1 | CWE-918 | 9.5.0 | Not exploited |
Why It Matters
Kiteworks sells a private data network for sharing sensitive files and email. Regulated firms and government agencies use it to move contracts, health records, and legal files. As a result, a breach of one appliance can expose the very data it was bought to protect.
The batch is also large. The advisory data lists 9 Critical, 35 High, 29 Medium, and 5 Low issues. Many of the worst ones need no login at all.
So far, no source confirms exploitation in the wild. Likewise, no public proof-of-concept has surfaced for any of the 78 CVEs. Even so, file transfer platforms have long been prime targets, so the patch window may be short.
How the Attacks Work
Account Takeover Through Password Reset
CVE-2026-102115 carries the top score of 9.8. Kiteworks Core failed to check a parameter in its password reset flow. An attacker who knows a user’s email can reset that password without the emailed link. The advisory warns this works “including where the account holds administrative privileges.” However, it only affects accounts with a locally stored password.
Certificate Hijacking in the Email Gateway
CVE-2026-102149 scores 9.4. The Email Protection Gateway let a certificate be tied to another user’s account. In turn, an attacker could read that user’s encrypted mail. Where certificate login is on, they could also sign in as that user.
Stored XSS Against Administrators
CVE-2026-102147 scores 9.3. An unauthenticated attacker can plant script content in Kiteworks Core. The script fires when an admin views the page. According to the advisory, this could grant “full administrative control, including the creation of a new administrative account.”
Admin Login Bypass and SSRF
CVE-2026-102106 lets attackers skip the password check on a gateway admin service. They could then create, change, or delete users and managed domains. Deleting a domain can even lock real admins out.
Five more Critical bugs are server-side request forgery flaws in the same gateway. Together, CVE-2026-102095 and CVE-2026-102102 through CVE-2026-102105 let a remote sender craft a message that makes the gateway fetch internal URLs. That includes cloud instance metadata endpoints, which often hold access keys.
Chains to Root
Many High-rated issues need a foothold first. Several let a low-privileged service account become root on the appliance. Others let a delegated admin raise their own role, or let a full admin run OS commands. CVE-2026-102125 allows code to escape the document conversion sandbox. CVE-2026-102120 lets an attacker jump from one cluster node to another. On their own, these need prior access. Chained with a Critical entry bug, though, they could turn a web flaw into full control of the box.
Forms and Lower-Risk Issues
The remaining Kiteworks vulnerabilities hit Secure Data Forms and Advanced Forms. They include SQL injection, insecure direct object references, open redirects, and username enumeration. Most score between 3 and 5, but they still widen the attack surface.
Affected Versions
The CVE records name three products. Each record lists a fix in either 9.5.0 or 9.5.1:
- Kiteworks Core: 16 records fixed in 9.5.0, and 12 more fixed in 9.5.1
- Kiteworks Email Protection Gateway: 12 records fixed in 9.5.0, and 7 more fixed in 9.5.1
- Kiteworks Secure Data Forms: one record fixed in 9.5.0, and others fixed in 9.5.1
Not every record states a version range. For that reason, 9.5.1 is the safe target for every deployment.
Patch and Mitigation Steps
Upgrade to 9.5.1
Admins should move every appliance to Kiteworks 9.5.1 now. The full list of fixes sits in the Kiteworks security advisories on GitHub. Clustered sites should patch every node, since several flaws move between nodes.
Reduce Exposure Until Then
- Limit admin interfaces and the appliance setup page to trusted networks.
- Audit password reset activity and look for resets with no matching email click.
- Review admin account lists and remove any accounts you did not create.
- Block the gateway from reaching cloud metadata endpoints at the network layer.
- Check delegated admin roles and trim them to what each person needs.
Finally, reset admin passwords and API credentials after patching if logs show anything odd. These Kiteworks vulnerabilities touch the data these systems exist to guard, so a fast upgrade is the best defense.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!