CVE-2026-24782

HIGH

Kiteworks < 9.3.0 - Authenticated SQL Injection in Secure Data Forms

Title source: llm
STIX 2.1

Description

Kiteworks is a private data network (PDN). Prior to version 9.3.0,ultiple SQL Injection vulnerabilities in Kiteworks Secure Data Forms could be exploited by an authenticated attacker with the FormBuilder role to retrieve information on or modify other users' form definitions and some global configuration parameters. Upgrade Kiteworks to version 9.3.0 or later to receive a patch.

References (1)

Core 1

Scores

CVSS v3 7.6
EPSS 0.0067
EPSS Percentile 46.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (2)
accellion/kiteworks < 9.3.0
kiteworks/Secure Data Forms < 9.3.0
Published Jun 01, 2026
Tracked Since Jun 02, 2026