← back
CVE-2026-23635mediumCWE-523

Kiteworks Secure Data Forms has a potential Unprotected Transport of Credentials

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.5epss 0.3%
exploitation probability
0.3%top 76% of all CVEs
observed exploitation
nono source reports it
In short

Kiteworks Secure Data Forms versions before 9.2.1 may transmit login credentials without proper encryption due to misconfigured security settings. This could allow attackers to intercept sensitive authentication information if they gain access to network traffic.

Technical detail

CWE-523 vulnerability in Kiteworks Secure Data Forms <9.2.1 allows unprotected transport of credentials through misconfigured security attributes. Attack vector is network-based; requires attacker to intercept communications between client and server. Successful exploitation results in exposure of authentication credentials.

Summary generated and translated by AI from the official description.
Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, a misconfiguration of the security attributes could potentially lead to Unprotected Transport of Credentials under certain circumstances. Upgrade Kiteworks to version 9.2.1 or later to receive a patch.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N