Description
Kiteworks Core contains a business logic flaw in a Kiteworks file-request feature allowed an authenticated user to send a request that appeared to originate from another user, because the server did not verify that the requester was authorized to act as the specified account. This could be used to solicit files or information from a recipient under a trusted identity; exploitation requires the feature to be enabled for the attacker's profile and the targeted recipient to act on the request.
Published: 2026-09-30
Score: 4.6 Medium
EPSS: n/a
KEV: No
Impact: User impersonation leading to unauthorized file requests
Action: Assess Impact
AI Analysis

Impact

Kiteworks Core contains a business logic flaw in a file-request feature that allows an authenticated user to send a request that appears to originate from another user because the server does not verify that the requester is authorized to act as the specified account. This flaw can be exploited to solicit files or information from a recipient under a trusted identity. The weakness is a classic example of authorization bypass (CWE-639).

Affected Systems

The affected system is Kiteworks Core. No specific product versions are listed, but the flaw exists wherever the file-request feature is enabled for a user profile.

Risk and Exploitability

The CVSS score of 4.6 indicates a moderate impact. An attacker must first have an authenticated user account with the file-request feature enabled, and the targeted recipient must act on the impersonated request. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, which suggests that widespread exploitation may not yet be observed. The likely attack vector involves legitimate, authenticated users abusing the feature to impersonate other users within the internal environment.

Generated by OpenCVE AI on September 30, 2026 at 21:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Disable the file-request feature for user accounts that should not have impersonation rights
  • Audit and limit permissions so that only authorized accounts can send file requests on behalf of others
  • Monitor file request logs for anomalous patterns indicating potential impersonation attempts

Generated by OpenCVE AI on September 30, 2026 at 21:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Kiteworks Core contains a business logic flaw in a Kiteworks file-request feature allowed an authenticated user to send a request that appeared to originate from another user, because the server did not verify that the requester was authorized to act as the specified account. This could be used to solicit files or information from a recipient under a trusted identity; exploitation requires the feature to be enabled for the attacker's profile and the targeted recipient to act on the request.
Title Kiteworks Core user impersonation in a file-request feature
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-09-30T20:24:29.840Z

Reserved: 2026-09-28T17:39:13.561Z

Link: CVE-2026-102107

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T21:16:57.613

Modified: 2026-09-30T21:16:57.613

Link: CVE-2026-102107

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T22:00:16Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key