CVE-2026-28271: Kiteworks Core is vulnerable to Server-Side Request Forgery (SSRF)
Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration functionality allows bypassing of SSRF protections through DNS rebinding attacks. Malicious administrators could exploit this to access internal services that should be restricted. Version 9.2.0 contains a patch for the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28271?
The severity of CVE-2026-28271 is considered significant due to its exploitation potential through DNS rebinding attacks.
How do I fix CVE-2026-28271?
To fix CVE-2026-28271, upgrade to Kiteworks Core version 9.2.0 or later.
What kind of attack does CVE-2026-28271 allow?
CVE-2026-28271 allows for Server-Side Request Forgery (SSRF) attacks due to improper configuration.
Who can exploit CVE-2026-28271?
Malicious administrators with access to the Kiteworks configuration can exploit CVE-2026-28271.
What are the consequences of exploiting CVE-2026-28271?
Exploitation of CVE-2026-28271 can lead to unauthorized access to internal services and sensitive data.