CVE-2026-23638
Last modified
CVE-2026-23638 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated attacker to tamper with the internal approval flow configurations of forms belonging to other users due to insufficient authorization checks on resource ownership. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated attacker to tamper with the internal approval flow configurations of forms belonging to other users due to insufficient authorization checks on resource ownership. Upgrade Kiteworks to version 9.3.0 or later to receive a patch.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Accellion | Kiteworks | < 9.3.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-23638?
How severe is CVE-2026-23638?
How do I fix CVE-2026-23638?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-23631Redis is an in-memory data structure store. In all versions …8.1
- CVE-2026-23632Gogs is an open source self-hosted Git service. In version 0…6.5
- CVE-2026-23633Gogs is an open source self-hosted Git service. In version 0…6.5
- CVE-2026-23634Pepr is a type safe K8s middleware. Prior to 1.0.5 , Pepr de…4.3
- CVE-2026-23635Kiteworks is a private data network (PDN). In Kiteworks Secu…6.5
- CVE-2026-23636Kiteworks is a private data network (PDN). In Kiteworks Secu…7.2
- CVE-2026-2364If a legitimate user confirms a self-update prompt or initia…7.3
- CVE-2026-23643CakePHP is a rapid development framework for PHP. The Pagina…5.4
- CVE-2026-23644esm.sh is a no-build content delivery network (CDN) for web …7.5
- CVE-2026-23645SiYuan is self-hosted, open source personal knowledge manage…6.1
- CVE-2026-23646OpenProject is an open-source, web-based project management …6.5
- CVE-2026-23647Glory RBG-100 recycler systems using the ISPK-08 software co…9.8
Are you affected by CVE-2026-23638?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
