Form-Rendering Interface Vulnerability in Advanced Forms by Kiteworks
CVE-2026-102121

8.6HIGH

Key Information:

Vendor

Kiteworks

Vendor
CVE Published:
30 September 2026

What is CVE-2026-102121?

The Advanced Forms component of Kiteworks has a vulnerability where its form-rendering interface is accessible without authentication. This allows anonymous users to retrieve published forms, resulting in the exposure of the form owner's profile details, including personal information and certain deployment configuration settings. Importantly, sensitive elements such as passwords, authentication tokens, and multi-factor secrets remain safeguarded. Organizations using this component should verify their current implementation to mitigate potential data exposure risks.

Affected Version(s)

Secure Data Forms 0 < 9.5.1

Secure Data Forms 9.5.1

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.