Junglewise Threat Intelligence

CVE-2026-24755: Kiteworks Secure Data Forms IDOR in collaborator permissions

CVE-2026-24755 · Severity: medium · CVSS 5.4 · Published 2026-06-01

Technologies: Kiteworks Secure Data Forms. Vendors: Kiteworks.

Executive brief

Kiteworks is a private data network platform used for secure file sharing and data exchange. A security flaw in the Secure Data Forms component allows a logged-in user to change the permissions and collaborator lists on forms owned by other people. This could lead to unauthorized individuals gaining access to sensitive data or legitimate users being locked out of their own forms.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in Kiteworks Secure Data Forms prior to version 9.3.0. The vulnerability is rooted in insufficient authorization checks on resource ownership when processing requests to modify form collaborators. An authenticated attacker can exploit this by manipulating resource identifiers (keys) in network requests to modify the permissions of forms they do not own. This allows for unauthorized modification of collaborator sets, potentially leading to data exposure or unauthorized access. The issue is addressed in Kiteworks version 9.3.0.

Affected products

  • Kiteworks Secure Data Forms < 9.3.0

Timeline

  • 2026-05-27: advisory: Vendor advisory published on GitHub
  • 2026-06-01: disclosed: CVE published in NVD dataset

References

Related threats