CVE-2026-24754

Kiteworks is a private data network (PDN). Prior to version 9.3.0, a stored XSS vulnerability in Kiteworks Secure Data Forms could allow an authenticated attacker to execute arbitrary JavaScript code in other users' sessions. Upgrade Kiteworks to version 9.3.0 or later to receive a patch.
Configurations

Configuration 1 (hide)

cpe:2.3:a:accellion:kiteworks:*:*:*:*:*:*:*:*

History

03 Jun 2026, 15:28

Type Values Removed Values Added
CPE cpe:2.3:a:accellion:kiteworks:*:*:*:*:*:*:*:*
First Time Accellion kiteworks
Accellion
References () https://github.com/kiteworks/security-advisories/security/advisories/GHSA-gxvv-hwgc-w7gh - () https://github.com/kiteworks/security-advisories/security/advisories/GHSA-gxvv-hwgc-w7gh - Vendor Advisory

01 Jun 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-01 23:16

Updated : 2026-06-03 15:28


NVD link : CVE-2026-24754

Mitre link : CVE-2026-24754

CVE.ORG link : CVE-2026-24754


JSON object : View

Products Affected

accellion

  • kiteworks
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')