Executive brief
Kiteworks is a private data network platform used for secure file sharing and data exchange. A security flaw in the Secure Data Forms component allows a logged-in user to modify or add data to forms belonging to other users. This could lead to unauthorized data manipulation and impact the integrity of information collected through the platform.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in Kiteworks Secure Data Forms prior to version 9.3.0. The flaw is caused by insufficient authorization checks on resource ownership when processing form submissions. A remote, authenticated attacker with low privileges can exploit this by modifying user-controlled keys (such as resource IDs) in network requests to add arbitrary submissions to forms belonging to other users. This is classified as an authorization bypass through a user-controlled key (CWE-639). The issue is resolved in Kiteworks version 9.3.0.
Affected products
- Kiteworks Secure Data Forms < 9.3.0
Timeline
- 2026-05-27: advisory: Vendor advisory published on GitHub
- 2026-06-01: disclosed: CVE published to NVD