Insecure Direct Object Reference in Kiteworks Secure Data Forms
CVE-2026-23638
6.5MEDIUM
What is CVE-2026-23638?
An Insecure Direct Object Reference (IDOR) vulnerability exists in Kiteworks Secure Data Forms, permitting authenticated attackers to manipulate internal approval flow configurations related to forms owned by other users. This issue stems from insufficient authorization checks, allowing unauthorized access to sensitive functionalities. To mitigate this risk, it is imperative for users to update to version 9.3.0 or higher.
Affected Version(s)
Kiteworks Secure Data Forms < 9.3.0
