No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 02 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Jun 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kiteworks
Kiteworks secure Data Forms |
|
| Vendors & Products |
Kiteworks
Kiteworks secure Data Forms |
Mon, 01 Jun 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated user to modify resources belonging to other users due to insufficient authorization checks on resource ownership. Upgrade Kiteworks to version 9.3.0 or later to receive a patch. | |
| Title | Kiteworks Secure Data Forms is vulnerable to Authorization Bypass Through User-Controlled Key | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-02T12:30:24.647Z
Reserved: 2026-01-26T19:06:16.060Z
Link: CVE-2026-24756
Updated: 2026-06-02T12:30:18.619Z
Status : Awaiting Analysis
Published: 2026-06-01T23:16:20.827
Modified: 2026-06-02T13:55:46.237
Link: CVE-2026-24756
No data.
OpenCVE Enrichment
Updated: 2026-06-02T00:30:26Z