Impact
A function in the Kiteworks Advanced Forms component can be accessed without any authentication, allowing an unauthenticated attacker to perform a limited set of internal service operations on the Kiteworks platform. The vulnerability does not provide access to user accounts, stored files, or form submissions, but it does expose internal service functionality that could be used for enumeration or further lateral movement.
Affected Systems
The affected product is Kiteworks Advanced Forms, part of the Kiteworks Secure Data Forms offering. No specific version information is provided in the advisory.
Risk and Exploitability
Based on the description, it is inferred that the vulnerability can be exploited from within the same network or from a compromised host that has network access to the Kiteworks platform. The likely attack vector is an unauthenticated request to the internal Advanced Forms endpoint. Because the endpoint does not enforce authentication, an attacker can trigger limited internal service operations. The CVSS score of 7.2 indicates a medium‑to‑high severity, and the EPSS score is reported as not available. The vulnerability is not listed in the CISA KEV catalog. While the flaw does not grant direct access to user accounts, stored files, or form submissions, the exposed internal service functionality could be used for enumeration or to facilitate lateral movement within the organization.
OpenCVE Enrichment