PT-2026-28067 · Kiteworks · Secure Data Forms
Published
2026-03-25
·
Updated
2026-03-25
·
CVE-2026-23636
CVSS v3.1
5.5
Medium
| AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L |
Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, the manager of a form could potentially exploit an Unrestricted Upload of File with Dangerous Type due to a missing validation. Upgrade Kiteworks to version 9.2.1 or later to receive a patch.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Secure Data Forms