Description
A SQL injection vulnerability existed in Kiteworks Secure Data Forms, where a value derived from the authenticated user's stored account data was incorporated into a database query without proper sanitization. An authenticated user could potentially influence that value to inject SQL. Exploitation requires an authenticated session and applies only to deployments where a specific optional feature is in use.
Published: 2026-09-30
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Unauthorized data access through authenticated SQL injection
Action: Patch
AI Analysis

Impact

The vulnerability is a classic parameter injection flaw where unsanitized user data is embedded into a backend query. If exploited, an attacker who is already authenticated could modify that data to inject arbitrary SQL, potentially reading, modifying, or deleting sensitive application data. The flaw is directly tied to CWE‑89 and does not provide remote code execution, but it can lead to significant confidentiality and integrity breaches for an impacted deployment.

Affected Systems

Kiteworks Secure Data Forms is the affected product. No specific version information is provided in the advisory, so all installations using the optional feature mentioned should be considered vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity, while the EPSS score is not available; therefore the current exploitation probability is unknown but could be nontrivial given the authentication requirement. The vulnerability is not listed in CISA’s KEV catalog, so there is no known widespread exploitation at this time. Likely exploitation requires an attacker to first authenticate to the application and then manipulate that authenticated session’s stored account data in the optional feature context.

Generated by OpenCVE AI on September 30, 2026 at 21:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Kiteworks Secure Data Forms to the vendor‑supplied version that addresses the SQL injection flaw. The referenced advisories provide the official patch or upgrade path.
  • If a patch is not yet available or cannot be applied immediately, disable the optional feature that triggers the vulnerable code path to eliminate the injection surface.
  • Implement monitoring of database query logs for anomalous activity that could indicate attempted injection and enforce strict input validation on stored account data before it is used in queries.

Generated by OpenCVE AI on September 30, 2026 at 21:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description A SQL injection vulnerability existed in Kiteworks Secure Data Forms, where a value derived from the authenticated user's stored account data was incorporated into a database query without proper sanitization. An authenticated user could potentially influence that value to inject SQL. Exploitation requires an authenticated session and applies only to deployments where a specific optional feature is in use.
Title Kiteworks Secure Data Forms SQL injection
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-09-30T20:23:36.117Z

Reserved: 2026-09-28T17:39:13.562Z

Link: CVE-2026-102109

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T21:16:57.860

Modified: 2026-09-30T21:16:57.860

Link: CVE-2026-102109

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T22:00:16Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')