PT-2026-28067 · Kiteworks · Secure Data Forms

Published

2026-03-25

·

Updated

2026-03-25

·

CVE-2026-23636

CVSS v3.1

5.5

Medium

AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L
Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, the manager of a form could potentially exploit an Unrestricted Upload of File with Dangerous Type due to a missing validation. Upgrade Kiteworks to version 9.2.1 or later to receive a patch.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2026-23636

Affected Products

Secure Data Forms