Executive brief
Kiteworks is a private data network platform used for secure file sharing and communications. A security flaw in the Secure Data Forms component could allow an authorized user to view metadata and email notification settings belonging to other users. While this does not allow access to the actual content of files, it results in the unauthorized exposure of configuration details and user information.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in Kiteworks Secure Data Forms due to insufficient authorization checks on resource ownership (CWE-639). An authenticated attacker can exploit this by manipulating resource identifiers in requests to the server, allowing them to retrieve metadata and email notification configurations belonging to other users. The attack is conducted over the network but is considered high complexity. The issue is resolved in Kiteworks version 9.3.0.
Affected products
- Kiteworks Secure Data Forms < 9.3.0
Timeline
- 2026-05-27: advisory: Vendor advisory published on GitHub
- 2026-06-01: disclosed: CVE published to NVD
- 2026-06-01: patched: Patch available in version 9.3.0