CVE-2026-23638 PUBLISHED

Kiteworks Secure Data Forms is vulnerable to Authorization Bypass Through User-Controlled Key

Assigner: GitHub_M
Reserved: 14.01.2026 Published: 01.06.2026 Updated: 01.06.2026

Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated attacker to tamper with the internal approval flow configurations of forms belonging to other users due to insufficient authorization checks on resource ownership. Upgrade Kiteworks to version 9.3.0 or later to receive a patch.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS Score: 6.5

Product Status

Vendor kiteworks
Product Secure Data Forms
Versions
  • Version < 9.3.0 is affected

References

Problem Types

  • CWE-639: Authorization Bypass Through User-Controlled Key CWE