PT-2026-28070 · Kiteworks · Kiteworks

CVE-2026-29092

·

Published

2026-03-25

·

Updated

2026-03-25

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Kiteworks versions prior to 9.2.1
Description A flaw in Kiteworks Email Protection Gateway session management permits blocked users to retain active sessions even after account deactivation, potentially enabling continued unauthorized access until session expiration. Kiteworks is a private data network (PDN).
Recommendations Upgrade to Kiteworks version 9.2.1 or later.

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-29092

Affected Products

Kiteworks