CVE-2026-24754

MEDIUM

Kiteworks < 9.3.0 - Authenticated Stored Cross-Site Scripting in Secure Data Forms

Title source: llm
STIX 2.1

Description

Kiteworks is a private data network (PDN). Prior to version 9.3.0, a stored XSS vulnerability in Kiteworks Secure Data Forms could allow an authenticated attacker to execute arbitrary JavaScript code in other users' sessions. Upgrade Kiteworks to version 9.3.0 or later to receive a patch.

References (1)

Core 1

Scores

CVSS v3 5.4
EPSS 0.0014
EPSS Percentile 3.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
accellion/kiteworks < 9.3.0
kiteworks/security-advisories < 9.3.0
Published Jun 01, 2026
Tracked Since Jun 02, 2026