Junglewise Threat Intelligence

CVE-2026-24752: Kiteworks Secure Data Forms reflected XSS in logging module

CVE-2026-24752 · Severity: high · CVSS 8.2 · Published 2026-06-01

Technologies: Kiteworks Secure Data Forms. Vendors: Kiteworks.

Executive brief

Kiteworks Secure Data Forms, a component of a private data network used for secure information exchange, is vulnerable to a security flaw that allows attackers to run malicious scripts in a user's browser. By tricking a legitimate user into clicking a specially crafted link, an attacker could potentially steal sensitive session information or perform unauthorized actions on the user's behalf. This could lead to unauthorized access to private data or compromise of user accounts within the network.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in the logging module of Kiteworks Secure Data Forms. The application fails to properly neutralize user-controllable input before rendering it in a web page, specifically within the logging functionality. An unauthenticated remote attacker can exploit this by sending a malicious URL to a victim; if the victim interacts with the link, the attacker's JavaScript executes within the context of the victim's session. This can lead to session hijacking (stealing cookies) or unauthorized data access. The vulnerability was addressed in version 9.3.0 by removing the affected code component.

Affected products

  • Kiteworks Secure Data Forms < 9.3.0

Timeline

  • 2026-05-27: advisory: Vendor advisory published on GitHub
  • 2026-06-01: disclosed: CVE published to NVD

References

Related threats