---
id: CVE-2026-102091
title: >-
  Kiteworks Secure Data Forms before version 9.5.0 is vulnerable to Server-Side
  Request Forgery that could allow an unauthenticated, remote attacker to make
  the server issue arbitrary outbound network requests and read back the
  responses
summary: >-
  Kiteworks Secure Data Forms before version 9.5.0 is vulnerable to Server-Side
  Request Forgery that could allow an unauthenticated, remote attacker to make
  the server issue arbitrary outbound network requests and read back the
  responses. …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-918
vendor: Kiteworks
product: Secure Data Forms
affected:
  - secure_data_forms < 9.5.0
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:16:55.617'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102091'
references:
  - url: >-
      https://github.com/kiteworks/security-advisories/security/advisories/GHSA-m8mj-m4fv-jmrh
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T21:25:07.819Z'
---

## Overview

Kiteworks Secure Data Forms before version 9.5.0 is vulnerable to Server-Side Request Forgery that could allow an unauthenticated, remote attacker to make the server issue arbitrary outbound network requests and read back the responses. This could potentially be used to reach internal-only services or other network-restricted resources.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
