CVE-2026-29092
MEDIUMKiteworks Email Protection Gateway has an Insufficient Session Expiration
Title source: cnaDescription
Kiteworks is a private data network (PDN). Prior to version 9.2.1, a vulnerability in Kiteworks Email Protection Gateway session management allows blocked users to maintain active sessions after their account is disabled. This could allow unauthorized access to continue until the session naturally expires. Upgrade Kiteworks to version 9.2.1 or later to receive a patch.
Scores
CVSS v3
4.9
EPSS
0.0004
EPSS Percentile
12.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-613
Status
published
Products (2)
accellion/kiteworks
< 9.2.1
kiteworks/Kiteworks Email Protection Gateway
< 9.2.1
Published
Mar 25, 2026
Tracked Since
Mar 25, 2026