securityonline.info 1 Oct 2026, 02:09 UTC

Kiteworks Fixes 78 Flaws Including Critical Admin Account Takeover

Kiteworks Fixes 78 Flaws Including Critical Admin Account Takeover
CyberSIXT Evidence Panel Source marked as original reporting

KITEWORKS has released a broad security patch covering 78 vulnerabilities across its Core platform, Email Protection Gateway and Secure Data Forms. Nine of the flaws are graded critical, with the most severe being CVE-2026-102115, a 9.8-rated password reset weakness that could allow an attacker to take over admin accounts.

The other high- to medium-severity issues include CVE-2026-102149 (9.4), CVE-2026-102147 (9.3), and several SSRF- and authentication-related flaws in the Email Protection Gateway and related components. At the time of reporting, there were no confirmed in-the-wild exploits, and the vendor notes that all issues are fixed in version 9.5.1 (with some records also addressed in 9.5.0).

The advisory details multiple attack paths, including an account takeover through password reset in Core (CVE-2026-102115), certificate hijacking in the Email Gateway (CVE-2026-102149) that could allow reading or signing into another user, and stored XSS against administrators (CVE-2026-102147) that could lead to full admin control. Other notable flaws involve admin login bypass and SSRF (CVE-2026-102106, plus related SSRF issues in CVEs 102095, 102102–102105).

Several chained or privilege-escalation vectors could, in combination with other flaws, grant root access or complete control over the appliance. Affected products include Kiteworks Core, Kiteworks Email Protection Gateway, and Kiteworks Secure Data Forms, with a safe target upgrade of 9.5.1 for all deployments. Practical response emphasises upgrading, restricting admin interfaces, auditing resets, reviewing admin accounts, blocking cloud metadata access, and reissuing credentials after patching.

View full article

Article by CyberSIXT