CVE-2026-24754

Kiteworks is a private data network (PDN). Prior to version 9.3.0, a stored XSS vulnerability in Kiteworks Secure Data Forms could allow an authenticated attacker to execute arbitrary JavaScript code in other users' sessions. Upgrade Kiteworks to version 9.3.0 or later to receive a patch.
Configurations

Configuration 1 (hide)

cpe:2.3:a:accellion:kiteworks:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-01 23:16

Updated : 2026-07-22 19:10


NVD link : CVE-2026-24754

Mitre link : CVE-2026-24754

CVE.ORG link : CVE-2026-24754


JSON object : View

Products Affected

accellion

  • kiteworks
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')