CVE-2025-53896: Kiteworks MFT is vulnerable to Insufficient Session Expiration
Published Nov 29, 2025
·Updated
Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, a bug in Kiteworks MFT could cause under certain circumstances that a user's active session would not properly time out due to inactivity. This issue has been patched in version 9.1.0.
Affected Software
2 affected components
Kiteworks MFT<9.1.0
Accellion Kiteworks Managed File Transfer<9.1.0
Remediation
Event History
Nov 29, 2025
CVE Published
via MITRE·02:24 AM
Data Sourced
via MITRE·02:24 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-53896?
CVE-2025-53896 has a medium severity level due to the session management issue that may affect user security.
2
How do I fix CVE-2025-53896?
To fix CVE-2025-53896, update your Kiteworks MFT to version 9.1.0 or later.
3
What are the potential impacts of CVE-2025-53896?
CVE-2025-53896 can lead to unauthorized access if a user's session does not time out properly after inactivity.
4
Is CVE-2025-53896 a persistent vulnerability?
No, CVE-2025-53896 is not a persistent vulnerability, but its impact can be significant if not addressed promptly.
5
Which versions of Kiteworks MFT are affected by CVE-2025-53896?
Kiteworks MFT versions prior to 9.1.0 are affected by CVE-2025-53896.