CVE-2026-24753
MEDIUMKiteworks < 9.3.0 - Authenticated Insecure Direct Object Reference in Secure Data Forms
Title source: llmDescription
Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated user to modify resources belonging to other users due to insufficient authorization checks on resource ownership. Upgrade Kiteworks to version 9.3.0 or later to receive a patch.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_confirm
https://github.com/kiteworks/security-advisories/security/advisories/GHSA-qmv7-28g4-hx9x
Scores
CVSS v3
6.5
EPSS
0.0017
EPSS Percentile
7.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-639
Status
published
Products (2)
accellion/kiteworks
< 9.3.0
kiteworks/Secure Data Forms
< 9.3.0
Published
Jun 01, 2026
Tracked Since
Jun 02, 2026