VDB

CVE-2026-102121

CVE-2026-102121 PUBLISHED CVSS 8.6 HIGH

Reported by cisa-cg · Published September 30, 2026

A form-rendering interface in the Advanced Forms component is reachable without authentication so that published forms can be displayed to anonymous visitors, but it returned more data than the form itself required. Anyone who knew the web address of a published form could potentially retrieve the form owner's Kiteworks account profile, including personal details, along with parts of the deployment's configuration settings; no passwords, authentication tokens, or multi-factor secrets were exposed.

Risk Scores

CVSS 3.1
8.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Affected Products

VendorProductVersions
KiteworksSecure Data Forms0, 9.5.1
KiteworksSecure Data Forms0, 9.5.1, 0

Timeline

  • Sep 30, 2026 Coalition ESS Score
  • Sep 30, 2026 CVE Published
  • Oct 1, 2026 EPSS Score
  • Oct 1, 2026 CVE Updated
  • Oct 2, 2026 EPSS Score
  • Oct 6, 2026 EPSS Score

References

  • url vendor-advisory
  • url third-party-advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›