CVE Watchtower


← Back to CVE List

CVE-2026-23638NVD

Description

Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated attacker to tamper with the internal approval flow configurations of forms belonging to other users due to insufficient authorization checks on resource ownership. Upgrade Kiteworks to version 9.3.0 or later to receive a patch.
Severity Level
MEDIUM (6.5)
Published Date
01/06/2026
Last Modified
03/06/2026
Exploitation Status
????