Description
A function in the Kiteworks Advanced Forms component was reachable without authentication. An unauthenticated attacker could potentially use it to carry out a limited set of internal service operations on the Kiteworks platform; it did not permit access to user accounts, stored files, or form submissions.
Published: 2026-09-30
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Unauthenticated internal service operations
Action: Apply Patch
AI Analysis

Impact

A function in the Kiteworks Advanced Forms component can be accessed without any authentication, allowing an unauthenticated attacker to perform a limited set of internal service operations on the Kiteworks platform. The vulnerability does not provide access to user accounts, stored files, or form submissions, but it does expose internal service functionality that could be used for enumeration or further lateral movement.

Affected Systems

The affected product is Kiteworks Advanced Forms, part of the Kiteworks Secure Data Forms offering. No specific version information is provided in the advisory.

Risk and Exploitability

Based on the description, it is inferred that the vulnerability can be exploited from within the same network or from a compromised host that has network access to the Kiteworks platform. The likely attack vector is an unauthenticated request to the internal Advanced Forms endpoint. Because the endpoint does not enforce authentication, an attacker can trigger limited internal service operations. The CVSS score of 7.2 indicates a medium‑to‑high severity, and the EPSS score is reported as not available. The vulnerability is not listed in the CISA KEV catalog. While the flaw does not grant direct access to user accounts, stored files, or form submissions, the exposed internal service functionality could be used for enumeration or to facilitate lateral movement within the organization.

Generated by OpenCVE AI on September 30, 2026 at 22:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy the vendor‑issued patch or update to a version that enforces authentication for the Advanced Forms endpoint.
  • If a patch is not yet available, block or limit external and internal access to the vulnerable endpoint using firewall rules or access control lists.
  • Enable detailed logging for all requests to the Advanced Forms endpoint and monitor for suspicious or unauthenticated traffic.
  • Review and harden authentication checks on all other Kiteworks components to ensure similar safeguards are in place.

Generated by OpenCVE AI on September 30, 2026 at 22:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
First Time appeared Kiteworks
Kiteworks secure Data Forms
Vendors & Products Kiteworks
Kiteworks secure Data Forms

Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A function in the Kiteworks Advanced Forms component was reachable without authentication. An unauthenticated attacker could potentially use it to carry out a limited set of internal service operations on the Kiteworks platform; it did not permit access to user accounts, stored files, or form submissions.
Title Kiteworks Secure Data Forms Missing Authentication for Critical Function
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Kiteworks Secure Data Forms
cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-09-30T20:09:36.216Z

Reserved: 2026-09-28T17:39:13.564Z

Link: CVE-2026-102150

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T21:17:03.880

Modified: 2026-10-01T02:17:43.350

Link: CVE-2026-102150

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T06:15:14Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function