CVE-2026-102150: Kiteworks Secure Data Forms Missing Authentication for Critical Function
Published Sep 30, 2026
·Updated
A function in the Kiteworks Advanced Forms component was reachable without authentication. An unauthenticated attacker could potentially use it to carry out a limited set of internal service operations on the Kiteworks platform; it did not permit access to user accounts, stored files, or form submissions.
Affected Software
1 affected component
Kiteworks Secure Data Forms
Event History
Sep 30, 2026
CVE Published
via MITRE·08:09 PM
Data Sourced
via MITRE·08:09 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness