Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.2

Kiteworks: Unauthorized Files Can Be Uploaded by Malicious Admins

CVE-2026-28270
Summary

Kiteworks, a private data network, had a security weakness that allowed a malicious administrator to upload any type of file without checking. This could lead to unauthorized files being added to the system. Update to version 9.2.0 to fix the issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
accellion kiteworks <= 9.2.0 –
Original title
Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration allows uploading of arbitrary files without proper validation. Malicious administrators...
Original description
Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration allows uploading of arbitrary files without proper validation. Malicious administrators could exploit this to upload unauthorized file types to the system. Version 9.2.0 contains a patch for the issue.
nvd CVSS3.1 7.2
Vulnerability type
CWE-434 Unrestricted File Upload
Published: 27 Feb 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026