Description
Kiteworks Secure Data Forms before version 9.5.0 is vulnerable to Server-Side Request Forgery that could allow an unauthenticated, remote attacker to make the server issue arbitrary outbound network requests and read back the responses. This could potentially be used to reach internal-only services or other network-restricted resources.
Published: 2026-09-30
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Remote request forgery that can access internal services
Action: Immediate Patch
AI Analysis

Impact

Kiteworks Secure Data Forms versions prior to 9.5.0 contain a server‑side request forgery flaw that allows an unauthenticated remote attacker to compel the application to perform arbitrary outbound HTTP requests and to retrieve the responses. This can enable the attacker to probe or exfiltrate data from internal‑only services or any resource reachable from the host, potentially compromising the confidentiality of internal data and the availability of those services. The weakness is a classic input‑validation flaw (CWE‑918).

Affected Systems

The affected product is Kiteworks Secure Data Forms. All releases older than 9.5.0 are vulnerable; no specific sub‑versions are listed, so any deployment built before the 9.5.0 release is at risk.

Risk and Exploitability

The CVSS score of 7.5 indicates a high risk level. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it from any network using unauthenticated access to the web interface; the exploitation path requires only sending a specially crafted request to the server, after which the server will forward the request to an arbitrary destination and send the response back to the attacker. Because the attack is trivial to trigger, the risk to organizations that expose the server to untrusted networks is significant.

Generated by OpenCVE AI on September 30, 2026 at 22:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Kiteworks Secure Data Forms to version 9.5.0 or later.
  • If an upgrade is not possible, block or disable the API endpoint that accepts user‑supplied URLs and restrict the server’s outbound network access to only needed destinations.
  • Implement network segmentation and firewall rules to prevent the application from reaching internal‑only services until a fix is applied.

Generated by OpenCVE AI on September 30, 2026 at 22:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Kiteworks
Kiteworks secure Data Forms
Vendors & Products Kiteworks
Kiteworks secure Data Forms

Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description Kiteworks Secure Data Forms before version 9.5.0 is vulnerable to Server-Side Request Forgery that could allow an unauthenticated, remote attacker to make the server issue arbitrary outbound network requests and read back the responses. This could potentially be used to reach internal-only services or other network-restricted resources.
Title Kiteworks Secure Data Forms server-side request forgery
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Kiteworks Secure Data Forms
cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-09-30T20:05:47.322Z

Reserved: 2026-09-28T17:39:13.560Z

Link: CVE-2026-102091

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T21:16:55.617

Modified: 2026-10-01T02:17:43.350

Link: CVE-2026-102091

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T05:00:12Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)