CVE-2026-24751: Kiteworks Secure Data Forms Vulnerable to Cross-site Scripting
Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an external attacker to trick a user into executing arbitrary JavaScript code. Upgrade Kiteworks to version 9.3.0 or later to receive a patch.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Kiteworks Secure Data Formsto a version that resolves this vulnerability.Fixed in 9.3.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24751?
The severity of CVE-2026-24751 is rated as high with a score of 8.2.
How do I fix CVE-2026-24751?
To fix CVE-2026-24751, upgrade Kiteworks to version 9.3.0 or later.
What type of vulnerability is CVE-2026-24751?
CVE-2026-24751 is a reflected cross-site scripting (XSS) vulnerability.
Who is affected by CVE-2026-24751?
Users of Kiteworks Secure Data Forms prior to version 9.3.0 are affected by CVE-2026-24751.
What could an attacker exploit in CVE-2026-24751?
An attacker could exploit CVE-2026-24751 to execute arbitrary JavaScript code on behalf of a user.