CVE-2026-24752: Kiteworks Secure Data Forms Vulnerable to Cross-site Scripting
Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an external attacker to trick a user into executing arbitrary JavaScript code. Upgrade Kiteworks to version 9.3.0 or later to receive a patch.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Kiteworks Secure Data Formsto a version that resolves this vulnerability.Fixed in 9.3.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24752?
The severity of CVE-2026-24752 is rated as high with a score of 8.2.
How do I fix CVE-2026-24752?
To fix CVE-2026-24752, you should upgrade Kiteworks to version 9.3.0 or later.
What type of vulnerability is CVE-2026-24752?
CVE-2026-24752 is a cross-site scripting (XSS) vulnerability.
What could an attacker achieve using CVE-2026-24752?
An attacker could potentially trick a user into executing arbitrary JavaScript code on their system.
Are all versions of Kiteworks affected by CVE-2026-24752?
Yes, all versions prior to 9.3.0 of Kiteworks Secure Data Forms are affected by CVE-2026-24752.