CVE-2026-102109

Summary

A SQL injection vulnerability existed in Kiteworks Secure Data Forms, where a value derived from the authenticated user's stored account data was incorporated into a database query without proper sanitization. An authenticated user could potentially influence that value to inject SQL. Exploitation requires an authenticated session and applies only to deployments where a specific optional feature is in use.

Affected Software

VendorProductVersion RangeStatus
KiteworksSecure Data Forms0 < 9.5.1affected
KiteworksSecure Data Forms9.5.1unaffected

Weaknesses

  • CWE-89: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

References