YWH YesWeHack LIVE
Kiteworks Public Bug Bounty Program
up to€50,000
Open on YesWeHack ↗
- listed
- before tracking
- tracked since
- 2026-09-20
- managed triage
- no
12 targets in scope
| asset | type | bounty | max sev | seen |
|---|---|---|---|---|
API Playground | domain | · | · | 2026-09-20 |
Email Protection Gateway (EPG) | domain | · | · | 2026-09-20 |
Kiteworks Core | domain | · | · | 2026-09-20 |
Managed File Transfer (MFT) | domain | · | · | 2026-09-20 |
Secure Data Forms (SDF, aka Advanced Forms) | domain | · | · | 2026-09-20 |
Kiteworks Desktop Client 2.0 | executable | · | · | 2026-09-20 |
Kiteworks for Desktop | executable | · | · | 2026-09-20 |
Kiteworks for Office Desktop | executable | · | · | 2026-09-20 |
Kiteworks for Outlook Desktop | executable | · | · | 2026-09-20 |
Kiteworks Android App | mobile | · | · | 2026-09-20 |
Kiteworks iOS App | mobile | · | · | 2026-09-20 |
Crown Jewel Heist | other | · | · | 2026-09-20 |
1 out of scope — black ICE, don't touch
Testing is only authorized on the targets listed as in scope. Any domain/property of Kiteworks not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Kiteworks, you can report it here. However, be aware that it is ineligible for rewards or points-based compensation.other
Change log
get alerts ↗No changes since we started tracking on 2026-09-20.