Junglewise Threat Intelligence

CVE-2026-23638: Kiteworks Secure Data Forms IDOR in approval flow configurations

CVE-2026-23638 · Severity: medium · CVSS 6.5 · Published 2026-06-01

Technologies: Kiteworks Secure Data Forms. Vendors: Kiteworks.

Executive brief

Kiteworks is a private data network platform used for secure file sharing and data exchange. A security flaw in the Secure Data Forms component allows a logged-in user to modify the approval settings of forms created by other users. This could allow an attacker to bypass internal business processes or redirect form approvals to unauthorized parties, potentially compromising the integrity of corporate workflows.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in Kiteworks Secure Data Forms prior to version 9.3.0. The vulnerability is caused by insufficient authorization checks on resource ownership when accessing or modifying form configurations. An authenticated attacker with low privileges can exploit this by manipulating resource identifiers (CWE-639) in network requests to modify the internal approval flow of forms they do not own. This allows for unauthorized modification of business logic and approval chains. The issue is resolved in Kiteworks version 9.3.0.

Affected products

  • Kiteworks Secure Data Forms < 9.3.0

Timeline

  • 2026-05-27: advisory: Vendor advisory published on GitHub
  • 2026-06-01: disclosed: CVE published in NVD dataset

References

Related threats