{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-24756","assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","state":"PUBLISHED","assignerShortName":"GitHub_M","dateReserved":"2026-01-26T19:06:16.060Z","datePublished":"2026-06-01T21:51:04.450Z","dateUpdated":"2026-06-02T12:30:24.647Z"},"containers":{"cna":{"title":"Kiteworks Secure Data Forms is vulnerable to Authorization Bypass Through User-Controlled Key","problemTypes":[{"descriptions":[{"cweId":"CWE-639","lang":"en","description":"CWE-639: Authorization Bypass Through User-Controlled Key","type":"CWE"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","version":"3.1"}}],"references":[{"name":"https://github.com/kiteworks/security-advisories/security/advisories/GHSA-jgvj-mf78-rxx8","tags":["x_refsource_CONFIRM"],"url":"https://github.com/kiteworks/security-advisories/security/advisories/GHSA-jgvj-mf78-rxx8"}],"affected":[{"vendor":"kiteworks","product":"Secure Data Forms","versions":[{"version":"< 9.3.0","status":"affected"}]}],"providerMetadata":{"orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M","dateUpdated":"2026-06-01T21:51:04.450Z"},"descriptions":[{"lang":"en","value":"Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated user to modify resources belonging to other users due to insufficient authorization checks on resource ownership. Upgrade Kiteworks to version 9.3.0 or later to receive a patch."}],"source":{"advisory":"GHSA-jgvj-mf78-rxx8","discovery":"UNKNOWN"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-06-02T12:30:13.726777Z","id":"CVE-2026-24756","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-06-02T12:30:24.647Z"}}]}}