VDB
CVE-2026-102091
CVE-2026-102091
PUBLISHED
CVSS 7.5 HIGH
Reported by cisa-cg · Published September 30, 2026
Kiteworks Secure Data Forms before version 9.5.0 is vulnerable to Server-Side Request Forgery that could allow an unauthenticated, remote attacker to make the server issue arbitrary outbound network requests and read back the responses. This could potentially be used to reach internal-only services or other network-restricted resources.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kiteworks | Secure Data Forms | 0, 9.5.0 |
| Kiteworks | Secure Data Forms | 0, 9.5.0, 0 |
Timeline
- Sep 30, 2026 Coalition ESS Score
- Sep 30, 2026 CVE Published
- Oct 1, 2026 EPSS Score
- Oct 2, 2026 EPSS Score
- Oct 6, 2026 EPSS Score
- Oct 8, 2026 CVE Updated