PT-2026-22394 · Kiteworks · Kiteworks

Icare

+1

·

Published

2026-02-27

·

Updated

2026-04-09

·

CVE-2026-28270

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kiteworks versions prior to 9.2.0
Description Kiteworks is a private data network (PDN). A configuration issue allows the upload of arbitrary files without proper validation. Malicious administrators could exploit this to upload unauthorized file types to the system.
Recommendations Update to version 9.2.0 or later.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2026-28270
GHSA-V8X9-VWG6-CJ45

Affected Products

Kiteworks