Kiteworks Core是美国Kiteworks公司的一款提供安全文件传输与内容治理能力的企业数据交换平台。 Kiteworks Core 9.2.0版本和9.2.1版本存在安全漏洞,该漏洞源于访问控制不当,可能导致未经授权的访问。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-24750 | 7.6 HIGH | Kiteworks Secure Data Forms vulnerable to Cross-site Scripting |
| CVE-2026-23635 | 6.5 MEDIUM | Kiteworks Secure Data Forms has a potential Unprotected Transport of Credentials |
| CVE-2026-23636 | 5.5 MEDIUM | Kiteworks Secure Data Forms is vulnerable to an Unrestricted Upload of File with Dangerous |
| CVE-2026-29092 | 4.9 MEDIUM | Kiteworks Email Protection Gateway has an Insufficient Session Expiration |
No comments yet