Junglewise Threat Intelligence

CVE-2026-24761: Kiteworks Secure Data Forms IDOR in metadata access

CVE-2026-24761 · Severity: low · CVSS 3.7 · Published 2026-06-01

Technologies: Kiteworks Secure Data Forms. Vendors: Kiteworks.

Executive brief

Kiteworks is a private data network platform used for secure file sharing and communications. A security flaw in the Secure Data Forms component could allow an authorized user to view metadata and email notification settings belonging to other users. While this does not allow access to the actual content of files, it results in the unauthorized exposure of configuration details and user information.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in Kiteworks Secure Data Forms due to insufficient authorization checks on resource ownership (CWE-639). An authenticated attacker can exploit this by manipulating resource identifiers in requests to the server, allowing them to retrieve metadata and email notification configurations belonging to other users. The attack is conducted over the network but is considered high complexity. The issue is resolved in Kiteworks version 9.3.0.

Affected products

  • Kiteworks Secure Data Forms < 9.3.0

Timeline

  • 2026-05-27: advisory: Vendor advisory published on GitHub
  • 2026-06-01: disclosed: CVE published to NVD
  • 2026-06-01: patched: Patch available in version 9.3.0

References

Related threats