CVE-2026-102150

Summary

A function in the Kiteworks Advanced Forms component was reachable without authentication. An unauthenticated attacker could potentially use it to carry out a limited set of internal service operations on the Kiteworks platform; it did not permit access to user accounts, stored files, or form submissions.

Affected Software

VendorProductVersion RangeStatus
KiteworksSecure Data Forms9.3.0 < 9.5.1affected
KiteworksSecure Data Forms9.5.1unaffected

Weaknesses

  • CWE-306: CWE-306 Missing Authentication for Critical Function

References