CVE-2026-102121: Kiteworks Secure Data Forms Exposure of Sensitive Information to an Unauthorized Actor
A form-rendering interface in the Advanced Forms component is reachable without authentication so that published forms can be displayed to anonymous visitors, but it returned more data than the form itself required. Anyone who knew the web address of a published form could potentially retrieve the form owner's Kiteworks account profile, including personal details, along with parts of the deployment's configuration settings; no passwords, authentication tokens, or multi-factor secrets were exposed.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments with published Advanced Forms are exposed because the form-rendering interface is intentionally reachable without authentication. An unauthenticated person must know the web address of a published form to attempt retrieval.
What information could be disclosed?
The response could include the form owner's Kiteworks account profile and personal details, plus portions of the deployment configuration. Passwords, authentication tokens, and multi-factor authentication secrets were not exposed.
Does exploitation require an authenticated account or user interaction?
No. The issue can be exploited remotely without authentication or user interaction, provided the attacker knows the URL of a published form.