Kiteworks Core contains a business logic flaw in a Kiteworks file-request feature allowed an authenticated user to send a request that appeared to originate from another user, because the server did not verify that the requester was authorized to act as the specified account. This could be used to solicit files or information from a recipient under a trusted identity; exploitation requires the feature to be enabled for the attacker's profile and the targeted recipient to act on the request.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 30 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Kiteworks Core contains a business logic flaw in a Kiteworks file-request feature allowed an authenticated user to send a request that appeared to originate from another user, because the server did not verify that the requester was authorized to act as the specified account. This could be used to solicit files or information from a recipient under a trusted identity; exploitation requires the feature to be enabled for the attacker's profile and the targeted recipient to act on the request.
Title Kiteworks Core user impersonation in a file-request feature
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-09-30T20:24:29.840Z

Reserved: 2026-09-28T17:39:13.561Z

Link: CVE-2026-102107

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T21:16:57.613

Modified: 2026-09-30T21:16:57.613

Link: CVE-2026-102107

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses