Kiteworks是美国Kiteworks公司的一个安全私有网络数据软件。 Kiteworks 9.2.1之前版本存在代码问题漏洞,该漏洞源于会话管理问题,可能导致被阻止用户在账户被禁用后仍保持活动会话,造成未经授权的访问。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| kiteworks | Kiteworks Email Protection Gateway | < 9.2.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-23514 | 8.8 HIGH | Kiteworks Core before 9.2.2 is vulnerable to Improper Ownership Management |
| CVE-2026-24750 | 7.6 HIGH | Kiteworks Secure Data Forms vulnerable to Cross-site Scripting |
| CVE-2026-23635 | 6.5 MEDIUM | Kiteworks Secure Data Forms has a potential Unprotected Transport of Credentials |
| CVE-2026-23636 | 5.5 MEDIUM | Kiteworks Secure Data Forms is vulnerable to an Unrestricted Upload of File with Dangerous |
No comments yet