CVE-2026-23636: Kiteworks Secure Data Forms is vulnerable to an Unrestricted Upload of File with Dangerous Type
Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, the manager of a form could potentially exploit an Unrestricted Upload of File with Dangerous Type due to a missing validation. Upgrade Kiteworks to version 9.2.1 or later to receive a patch.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23636?
CVE-2026-23636 is classified as a high-severity vulnerability due to the risk associated with unrestricted file uploads.
How do I fix CVE-2026-23636?
To fix CVE-2026-23636, upgrade Kiteworks Secure Data Forms to version 9.2.1 or later.
What types of files are considered dangerous in CVE-2026-23636?
CVE-2026-23636 is related to unrestricted uploads of files that can execute code, such as PHP, EXE, or certain script files.
Who is affected by CVE-2026-23636?
Any installation of Kiteworks Secure Data Forms prior to version 9.2.1 is affected by CVE-2026-23636.
What can attackers do with CVE-2026-23636?
Attackers can exploit CVE-2026-23636 to upload malicious files, potentially leading to remote code execution on the vulnerable system.