Junglewise Threat Intelligence

CVE-2026-24782: Kiteworks Secure Data Forms SQL injection

CVE-2026-24782 · Severity: high · CVSS 7.6 · Published 2026-06-01

Technologies: KiteworksBase Secure Data Forms. Vendors: Kiteworks.

Executive brief

Kiteworks is a private data network platform used for secure file sharing and data exchange. A security flaw in its Secure Data Forms component allows certain authorized users to bypass data protections and access or change form definitions belonging to other users. This could lead to the unauthorized modification of business forms or the exposure of sensitive configuration settings, potentially compromising the integrity of data collection processes.

Technical details

Multiple SQL injection vulnerabilities exist in the Kiteworks Secure Data Forms component due to improper neutralization of special elements used in SQL commands (CWE-89). An authenticated attacker with the 'FormBuilder' role can exploit these flaws via network requests to execute arbitrary SQL queries. Successful exploitation allows the attacker to retrieve or modify form definitions belonging to other users and alter certain global configuration parameters. The vulnerability is patched in Kiteworks version 9.3.0.

Affected products

  • KiteworksBase Secure Data Forms < 9.3.0

Timeline

  • 2026-05-27: advisory: Vendor advisory published on GitHub
  • 2026-06-01: disclosed: CVE published to NVD
  • 2026-06-01: patched: Version 9.3.0 released with fix

References

Related threats