PT-2026-45505 · Kiteworks · Kiteworks Secure Data Forms+1

Kw-Fscheuer

·

Published

2026-06-01

·

Updated

2026-06-01

·

CVE-2026-23638

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated attacker to tamper with the internal approval flow configurations of forms belonging to other users due to insufficient authorization checks on resource ownership. Upgrade Kiteworks to version 9.3.0 or later to receive a patch.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-23638

Affected Products

Kiteworks Secure Data Forms
Secure Data Forms