CVE-2026-102121: Kiteworks Secure Data Forms Exposure of Sensitive Information to an Unauthorized Actor

Published Sep 30, 2026
·
Updated

A form-rendering interface in the Advanced Forms component is reachable without authentication so that published forms can be displayed to anonymous visitors, but it returned more data than the form itself required. Anyone who knew the web address of a published form could potentially retrieve the form owner's Kiteworks account profile, including personal details, along with parts of the deployment's configuration settings; no passwords, authentication tokens, or multi-factor secrets were exposed.

Affected Software

1 affected component
Kiteworks Secure Data Forms

Event History

Sep 30, 2026
CVE Published
via MITRE·08:17 PM
Data Sourced
via MITRE·08:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Deployments with published Advanced Forms are exposed because the form-rendering interface is intentionally reachable without authentication. An unauthenticated person must know the web address of a published form to attempt retrieval.

2

What information could be disclosed?

The response could include the form owner's Kiteworks account profile and personal details, plus portions of the deployment configuration. Passwords, authentication tokens, and multi-factor authentication secrets were not exposed.

3

Does exploitation require an authenticated account or user interaction?

No. The issue can be exploited remotely without authentication or user interaction, provided the attacker knows the URL of a published form.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203