CVE-2026-28272: Kiteworks Email Protection Gateway has a Cross-site Scripting vulnerability
Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks Email Protection Gateway allows authenticated administrators to inject malicious scripts through a configuration interface. The stored script executes when users interact with the affected user interface. Version 9.2.0 contains a patch for the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28272?
CVE-2026-28272 is considered a high-severity vulnerability due to its potential for Cross-site Scripting attacks.
How do I fix CVE-2026-28272?
To fix CVE-2026-28272, upgrade the Kiteworks Email Protection Gateway to version 9.2.0 or later.
Who is affected by CVE-2026-28272?
Authenticated administrators using Kiteworks Email Protection Gateway versions prior to 9.2.0 are affected by CVE-2026-28272.
What type of vulnerability is CVE-2026-28272?
CVE-2026-28272 is a Cross-site Scripting (XSS) vulnerability.
Can CVE-2026-28272 be exploited remotely?
CVE-2026-28272 can potentially be exploited by authenticated users through the configuration interface of the affected software.