Executive brief
Kiteworks Secure Data Forms, a platform used for secure data collection and private networking, contains a security flaw that allows users to modify data belonging to others. An authorized user could potentially tamper with workspaces or resources they do not own, compromising the integrity of information stored on the network. This issue is resolved in version 9.3.0.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability (CWE-639) exists in Kiteworks Secure Data Forms prior to version 9.3.0. The application fails to perform sufficient authorization checks on resource ownership when processing user-controlled keys. An authenticated attacker with low privileges can exploit this over the network to modify or tamper with workspaces and resources belonging to other users. The vulnerability specifically impacts data integrity but does not directly facilitate data exfiltration or service disruption. The issue is addressed in Kiteworks version 9.3.0.
Affected products
- Kiteworks Secure Data Forms < 9.3.0
Timeline
- 2026-05-27: advisory: Original GitHub advisory published by Kiteworks
- 2026-06-01: disclosed: CVE published to NVD dataset
- 2026-06-01: patched: Patch available in version 9.3.0