
Kiteworks public bug bounty on YesWeHack
Kiteworks pays up to $50,000 for a critical bug in its content platform. Reports go through YesWeHack at any time.
The Kiteworks Public Bug Bounty Program pays researchers who report vulnerabilities in the Kiteworks platform. YesWeHack hosts the program. The page lists a maximum reward of $50,000. It also describes a $25,000 bonus, added to the high reward grid, for a new unauthenticated remote code execution bug that reaches root on the Kiteworks Core appliance. A table for that case pays $50,000 at a CVSS score of 10.0 and steps down to $35,000 at 9.0.
The program page says it launched in September 2026 and was last updated on September 10, 2026. There is no closing date. The same page shows reports in the last day and the last week, so it is still taking submissions.
You must be the first person to report the issue, and you must not be a current or former employee or contractor. Send the report only through YesWeHack, no later than 24 hours after you find it, with a clear description and steps to reproduce. Denial of service testing, changes to infrastructure, and public disclosure are forbidden. Testing stays on the hunting environments named in the program.
Kiteworks says it is mainly interested in high and critical issues, including privilege escalation, remote code execution, cross site scripting with a real impact, and LDAP injection. The scope covers the core node, the email protection gateway, advanced forms, managed file transfer, and the user endpoint. An XSS report needs a shown impact, not only a popup alert.