CVE-2026-102121High· 8.6▾ TwilightA form-rendering interface in the Advanced Forms component is reachable without authentication so that published forms can be displayed to anonymous visitors, but it returned more data than the form itself required. Anyone who knew the w…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 47.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A form-rendering interface in the Advanced Forms component is reachable without authentication so that published forms can be displayed to anonymous visitors, but it returned more data than the form itself required. Anyone who knew the web address of a published form could potentially retrieve the form owner's Kiteworks account profile, including personal details, along with parts of the deployment's configuration settings; no passwords, authentication tokens, or multi-factor secrets were exposed.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102150High· 7.2A function in the Kiteworks Advanced Forms component was reachable without authentication
CVE-2026-102149Critical· 9.4Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could be assigned to
CVE-2026-102144Medium· 5.3A resource exhaustion vulnerability in Kiteworks Email Protection Gateway allowed an unauthenticated remote attacker to repeatedly trigger a comparatively expensive server-side operation, causing a partial denial of service.
CVE-2026-102143High· 7.5An unauthenticated attacker could cause a file with attacker-controlled content to be written to the appliance filesystem through an administrative upload handler that did not properly authenticate the request
CVE-2026-102124Medium· 6.5A Kiteworks appliance setup interface did not enforce authentication once the appliance had completed initial configuration
CVE-2026-102110Medium· 5.9An endpoint used during initial appliance setup did not require authentication and did not correctly enforce its intended state precondition, so during the initial activation window an unauthenticated network attacker could repeatedly re…