CVE-2026-28270: Kiteworks Core has an Unrestricted Upload of File with Dangerous Type
Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration allows uploading of arbitrary files without proper validation. Malicious administrators could exploit this to upload unauthorized file types to the system. Version 9.2.0 contains a patch for the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28270?
CVE-2026-28270 is considered a high severity vulnerability due to potential exploitation by malicious administrators.
How do I fix CVE-2026-28270?
To fix CVE-2026-28270, upgrade Kiteworks Core to version 9.2.0 or later.
What type of vulnerability is CVE-2026-28270?
CVE-2026-28270 is an unrestricted file upload vulnerability that allows uploading of dangerous file types.
Who is affected by CVE-2026-28270?
CVE-2026-28270 affects all versions of Kiteworks Core prior to 9.2.0.
What could an attacker do with CVE-2026-28270?
An attacker could exploit CVE-2026-28270 to upload malicious files, potentially leading to further compromising of the system.