No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 01 Jun 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kiteworks
Kiteworks secure Data Forms |
|
| Vendors & Products |
Kiteworks
Kiteworks secure Data Forms |
Mon, 01 Jun 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Jun 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated attacker to tamper with the internal approval flow configurations of forms belonging to other users due to insufficient authorization checks on resource ownership. Upgrade Kiteworks to version 9.3.0 or later to receive a patch. | |
| Title | Kiteworks Secure Data Forms is vulnerable to Authorization Bypass Through User-Controlled Key | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-01T19:04:22.955Z
Reserved: 2026-01-14T16:08:37.483Z
Link: CVE-2026-23638
Updated: 2026-06-01T19:01:40.007Z
Status : Received
Published: 2026-06-01T19:16:22.140
Modified: 2026-06-01T19:16:22.140
Link: CVE-2026-23638
No data.
OpenCVE Enrichment
Updated: 2026-06-01T21:30:26Z