CVE-2026-102121

HIGH Status: Received

CVSS Scores

CVSS v3.x Base Score
8.6
HIGH

Description

A form-rendering interface in the Advanced Forms component is reachable without authentication so that published forms can be displayed to anonymous visitors, but it returned more data than the form itself required. Anyone who knew the web address of a published form could potentially retrieve the form owner's Kiteworks account profile, including personal details, along with parts of the deployment's configuration settings; no passwords, authentication tokens, or multi-factor secrets were exposed.

Published
September 30, 2026 9:17 PM
Last Modified
September 30, 2026 9:17 PM
Source
9119a7d8-5eab-497f-8521-727c672e3725

Weaknesses (CWE)

CWE-200 CWE-306

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.