Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated attacker to tamper with the internal approval flow configurations of forms belonging to other users due to insufficient authorization checks on resource ownership. Upgrade Kiteworks to version 9.3.0 or later to receive a patch.
Metrics
Affected Vendors & Products
References
History
Mon, 01 Jun 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kiteworks
Kiteworks secure Data Forms |
|
| Vendors & Products |
Kiteworks
Kiteworks secure Data Forms |
Mon, 01 Jun 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Jun 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated attacker to tamper with the internal approval flow configurations of forms belonging to other users due to insufficient authorization checks on resource ownership. Upgrade Kiteworks to version 9.3.0 or later to receive a patch. | |
| Title | Kiteworks Secure Data Forms is vulnerable to Authorization Bypass Through User-Controlled Key | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-01T19:04:22.955Z
Reserved: 2026-01-14T16:08:37.483Z
Link: CVE-2026-23638
Updated: 2026-06-01T19:01:40.007Z
Status : Received
Published: 2026-06-01T19:16:22.140
Modified: 2026-06-01T19:16:22.140
Link: CVE-2026-23638
No data.
OpenCVE Enrichment
Updated: 2026-06-01T21:30:26Z