Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated user to access metadata of resources belonging to other users due to insufficient authorization checks on resource ownership. Upgrade Kiteworks to version 9.3.0 or later to receive a patch.
Metrics
Affected Vendors & Products
References
History
Mon, 01 Jun 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated user to access metadata of resources belonging to other users due to insufficient authorization checks on resource ownership. Upgrade Kiteworks to version 9.3.0 or later to receive a patch. | |
| Title | Kiteworks Secure Data Forms is vulnerable to Authorization Bypass Through User-Controlled Key | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-01T21:52:53.195Z
Reserved: 2026-01-26T21:06:47.867Z
Link: CVE-2026-24761
No data.
Status : Received
Published: 2026-06-01T23:16:20.960
Modified: 2026-06-01T23:16:20.960
Link: CVE-2026-24761
No data.
OpenCVE Enrichment
Updated: 2026-06-01T23:30:12Z